Hackers exploited critical WordPress flaw within hours of the patch
The CVE-2026-87902 flaw, rated CVSS 9.2, lets an unauthenticated attacker run code on a server. WordPress fixed it in version 7.1.2 on 22 September and backported patches to every branch down to 4.7, but attacks began at 11:49 UTC the same day.
- CVE-2026-87902 in get_page_template() allows unauthenticated remote code execution
- CVSS 9.2; patched 22 September in WordPress 7.1.2 and branches back to 4.7
- First attacks hit at 11:49 UTC, peaking 23 September at 10x the initial volume
- Previdian logged 68 exploitation attempts; few actual compromises expected
Read next
Security