Skip to content
Tech News
← Back to articles

Attackers exploit WordPress CVE-2026-87902 within hours of patch release

read original get YubiKey 5C NFC Security Key → more articles
GoKawiil Brief

Security firm Patchstack says threat actors began exploiting a critical WordPress path traversal flaw, CVE-2026-87902, to write files that execute shell commands, after initial reconnaissance traffic surged tenfold. The bug, discovered by researcher Robert Ressl and rated 9.2/10 in severity, allows unauthenticated attackers to trick get_page_template() into loading arbitrary local PHP files under certain theme and server configurations. WordPress patched the issue in version 7.1.2 and backported fixes to branches as old as 4.7.

Why It Matters

GoKawiil's interpretation of the reporting above, not reported fact.

The rapid pivot from scanning to active exploitation—starting less than five hours after the patch shipped—suggests attackers are reverse-engineering fixes quickly to hit unpatched sites, a pattern common with widely-used CMS platforms. Because the flaw affects default configurations like the official PHP Docker image and older cPanel setups, the exposure could be broader than typical WordPress vulnerabilities, according to the advisory's technical details.

Key Takeaways
Worth a Look

YubiKey 5C NFC Security Key — With attackers actively exploiting WordPress flaws to gain code execution, locking down admin access with hardware-backed two-factor authentication is a smart layer of defense. A YubiKey helps ensure that even if credentials are phished or leaked, unauthorized logins to your WordPress dashboard are blocked. It's a practical step site owners can take right now while patches roll out.

See YubiKey 5C NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

Source: bleepingcomputer.com, 2026-09-23

Published there as: “Hackers start exploiting critical WordPress flaw for code execution”

Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.