MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-24 · via The Hacker News

Critical WordPress Vulnerability Under Active Attack Immediately After Disclosure

Image via The Hacker News
Image via The Hacker News

Threat actors are actively exploiting a critical WordPress vulnerability, CVE-2026-87902, with a CVSS score of 9.2. The flaw allows unauthenticated attackers to achieve remote code execution by manipulating page-template resolution to include a chosen local PHP file. Exploitation began within hours of public disclosure.

Expanded Detail

The disclosure of CVE-2026-87902, a critical flaw in WordPress with a CVSS score of 9.2, has triggered immediate, active exploitation. The vulnerability enables unauthenticated remote code execution by abusing page-template resolution to load a locally chosen PHP file. Within hours of public details emerging, threat actors moved to weaponize the flaw, underscoring the speed at which known vulnerabilities are targeted. This incident highlights the persistent risk facing the vast ecosystem of sites built on WordPress, where a single unpatched component can expose entire infrastructures to compromise. The rapid exploitation timeline emphasizes the necessity for administrators to prioritize patch deployment and monitor for indicators of intrusion, as the window between disclosure and attack continues to shrink.

Context

This vulnerability could affect millions of WordPress-powered websites, from small blogs to enterprise platforms, potentially enabling attackers to seize control, steal data, or deploy malware. Site owners and users may face data breaches, service disruptions, and reputational harm. The speed of exploitation suggests that unpatched systems are at immediate risk, and the broader cybersecurity community may see an increase in related attacks. However, the impact depends on how quickly hosting providers and administrators apply available fixes, as well as on the effectiveness of existing security layers.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at The Hacker News →
Related stories
WordPress zero-day under active attack as exploit chain moves to file writes · Cybersecurity
WordPress Core CSRF bug enables remote code execution via theme preview · Cybersecurity
Check Point confirms active attacks on VPN gateway vulnerability, adds second zero-day to advisory · Cybersecurity
Arista fixes critical VeloCloud Orchestrator flaw under active attack · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure.” Browse more stories.