chiprook
← Security
SecuritySeptember 24, 2026, 12:36

WordPress CVE-2026-87902 Exploited Within Hours of Disclosure

Threat actors have begun actively exploiting a critical WordPress vulnerability, CVE-2026-87902 (CVSS 9.2), within hours of public disclosure. The flaw lets an unauthenticated attacker achieve remote code execution by making get_page_template() resolution include a chosen readable local .php file.

WordPress CVE-2026-87902 Exploited Within Hours of Disclosure
#WordPress
Read next
Security

GitHub lost 3,800 repos after malicious VSCode extension

Security

Mullvad leak: only 284 exit-IP combinations instead of trillions

Security

US contractor exposed path to 50M immigration records

Security

SANS: Data Overtakes Skills as Top Threat Hunting Barrier