chiprook
← Security
SecuritySeptember 28, 2026, 18:32

Hackers exploited critical WordPress flaw within hours of the patch

The CVE-2026-87902 flaw, rated CVSS 9.2, lets an unauthenticated attacker run code on a server. WordPress fixed it in version 7.1.2 on 22 September and backported patches to every branch down to 4.7, but attacks began at 11:49 UTC the same day.

Hackers exploited critical WordPress flaw within hours of the patch
#WordPress#Patchstack
Read next
Security

WordPress CVE-2026-87902 Exploited Within Hours of Disclosure

Security

Hackers now exploit critical Roundcube flaw in code injection attacks

Security

WordPress Patches Critical Flaw Enabling Code Execution on Some Servers

Security

Elementor WordPress flaw lets attackers create admin accounts