Attackers have begun exploiting the critical WordPress vulnerability CVE-2026-87902 within hours of its public disclosure, enabling unauthenticated remote code execution under specific conditions involving theme directory naming and readable local PHP files. Security firms Previdian and Patchstack have observed active exploitation attempts resulting in arbitrary file writes and web shell deployments, prompting urgent recommendations for WordPress site administrators to update to version 7.1.2 or later and monitor for malicious activity.
https://thehackernews.com/2026/09/attackers-exploit-wordpress-cve-2026.html

