WordPress
CISA Adds WordPress Core Remote File Inclusion to KEV
09/25/2026
CISA lists an exploited WordPress template-resolution flaw that can include local PHP files under specific theme and server conditions. Update the affected core branch, preserve suspicious files and logs, and conduct forensic triage.
WordPress Core Under Active Exploitation: Verify the Fix and Investigate Possible Compromise
08/24/2026
Updating WordPress core is only the first step. Use this checklist to verify versions, checksums, users, cron, uploads, logs, WAF data, and rebuild criteria.

