Hackers start exploiting critical WordPress flaw for code execution
Reported exploitedWordPressOur summary
Threat actors are actively exploiting the critical unauthenticated path traversal flaw CVE-2026-87902 in WordPress to write PHP files that can run shell commands when accessed. WordPress fixed the issue in version 7.1.2 and backported fixes to branches down to 4.7; administrators should update promptly and review logs for double-encoded traversal probes and suspicious files in /tmp or /var/tmp.
Read at BleepingComputer
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.