Home / Sep 25, 2026 / Story
0
#2 The Hacker News general September 24, 2026 at 05:36 UTC

Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure

By [email protected] (The Hacker News)

AI Summary

CVE-2026-87902, a critical WordPress path traversal vulnerability with a CVSS score of 9.2, was actively exploited within hours of public disclosure, allowing unauthenticated attackers to achieve remote code execution via manipulation of the get_page_template() function to include arbitrary local PHP files. The rapid weaponization underscores the shrinking window between disclosure and exploitation for WordPress flaws. Administrators running affected WordPress installations should apply patches immediately.

Relevance score: 87.0/100

# More from September 25