CVE Tools

Hackers start exploiting critical WordPress flaw for code execution

BleepingComputerBy Bill Toulas

Reported exploitedWordPress

Our summary

Threat actors are actively exploiting the critical unauthenticated path traversal flaw CVE-2026-87902 in WordPress to write PHP files that can run shell commands when accessed. WordPress fixed the issue in version 7.1.2 and backported fixes to branches down to 4.7; administrators should update promptly and review logs for double-encoded traversal probes and suspicious files in /tmp or /var/tmp.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store