Threat actors began exploiting a critical WordPress vulnerability within hours of its public disclosure. Tracked as CVE-2026-87902 (CVSS score: 9.2), the flaw lets an unauthenticated attacker achieve remote code execution (RCE) under specific server and theme conditions. The first attempt was logged on September 22, 2026, at 11:49 a.m. UTC, the same day patches were […]

Key Takeaways
Critical flaw: CVE-2026-87902 (CVSS 9.2) lets unauthenticated attackers achieve remote code execution on WordPress.
Rapid exploitation: The first attack was logged on September 22, 2026, the same day patches shipped.
Attack volume: Previdian recorded 68 exploitation attempts in its telemetry.
Threat actors began exploiting a critical WordPress vulnerability within hours of its public disclosure. Tracked as CVE-2026-87902 (CVSS score: 9.2), the flaw lets an unauthenticated attacker achieve remote code execution (RCE) under specific server and theme conditions.
The first attempt was logged on September 22, 2026, at 11:49 a.m. UTC, the same day patches were released.
How CVE-2026-87902 Enables Remote Code ExecutionAccording to the WordPress advisory, an unauthenticated attacker can manipulate page-template resolution in get_page_template() so it includes a chosen, readable local .php file from outside the active theme directories.
Two preconditions apply for this vulnerability:
Previdian reported exploitation attempts against its honeypot network, and its telemetry recorded 68 exploitation attempts from a U.S.- and an Indonesia-based IP.
Patchstack corroborated the findings and warned that requests had expanded from reconnaissance to active exploitation that writes PHP files to disk.
Which WordPress Versions to Install Now"We're likely to see mass-exploitation attempts, but relatively few actual compromises," Previdian founder and CEO Ryan Dewhurst has said. While the platform has auto-updates enabled by default, WordPress administrators should:
A July report warned that an unauthenticated WordPress Exploit, Wp2shell, needed no login or plugins, while an “essential plugin” backdoor that was disseminated to over 20,000 active WordPress installations was flagged in April.
Explore More
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | WordPress-Lücke nur Stunden nach Patch attackiert | 0 | 13.45 | 25-09-2026 |
| 2 | Уязвимости в LXD, Incus, GitLab, Radicle, ядре Linux, WordPress, OpenVPN, Flatpak, NTFS-3G, FreeRDP, CUPS, Dovecot | 0 | 12.49 | 27-09-2026 |
| 3 | Cloudflare Fixes Cross-Tenant Data Exposure Bug in Containers | 0 | 11.48 | 25-09-2026 |
| 4 | Revolut breach exposes authentication-authorization gap | 0 | 18.86 | 17-09-2026 |
| 5 | Elsevier LAPSUS$ Redirect Attack: Visitors Sent to Leak Page Instead of Journals | 0 | 10.81 | 24-09-2026 |
| 6 | Jetzt updaten! Attacken auf Roundcube-Webmail-Instanzen beobachtet | 0 | 14.76 | 25-09-2026 |
| 7 | В Воронежской области пять часов действовал режим угрозы атаки БПЛА | 0 | 9.6 | 27-09-2026 |
| 8 | Bitget 被盗走价值 3.875 亿美元加密货币 | 0 | 31.13 | 27-09-2026 |
| 9 | MacSync macOS Stealer Returns With Binary Payloads and iCloud Tricks | 0 | 13 | 25-09-2026 |
| 10 | FreeBSD-EN-26:21.openssl | 0 | 100 | 25-08-2026 |