The flaw is WordPress's; your php.ini decides the exposure
CVE-2026-87902 entered CISA's Known Exploited Vulnerabilities catalogue on 25 September, three days after the advisory and a proof of concept went public. It is a 9.2 and it is WordPress core, patched across 25 branches down to 4.7.37 (December 2016). But 9.2 measures the damage, not your exposure: the CVSS 4.0 vector itself carries AT:P — "conditions are required" — and none of the deciding conditions belong to WordPress. A PHP directive, a PEAR file and a directory inside your active theme. What each one checks, why the obvious command for looking at it from a shell returns a false answer — we measured it on a box running PHP 8.3.6 — and what NOT to do if you suspect it already happened.