#2
The Hacker News
general
September 24, 2026 at 05:36 UTC
Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure
By [email protected] (The Hacker News)
AI Summary
CVE-2026-87902, a critical WordPress path traversal vulnerability with a CVSS score of 9.2, was actively exploited within hours of public disclosure, allowing unauthenticated attackers to achieve remote code execution via manipulation of the get_page_template() function to include arbitrary local PHP files. The rapid weaponization underscores the shrinking window between disclosure and exploitation for WordPress flaws. Administrators running affected WordPress installations should apply patches immediately.
Relevance score: 87.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →