Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

WordPress CVE-2026-87902 Under Active Attack: Critical RCE Flaw Exploited Within Hours

Дата публикации: 24-09-2026 10:01:09

Threat actors began exploiting a critical WordPress vulnerability within hours of its public disclosure. Tracked as CVE-2026-87902 (CVSS score: 9.2), the flaw lets an unauthenticated attacker achieve remote code execution (RCE) under specific server and theme conditions.  The first attempt was logged on September 22, 2026, at 11:49 a.m. UTC, the same day patches were […]

Основное содержимое страницы с новостью.

Website Structure - Exposed Entry Point - Attacker - Red-Lit Passage - Modular Web Components

Key Takeaways

  • Critical flaw: CVE-2026-87902 (CVSS 9.2) lets unauthenticated attackers achieve remote code execution on WordPress.

  • Rapid exploitation: The first attack was logged on September 22, 2026, the same day patches shipped.

  • Attack volume: Previdian recorded 68 exploitation attempts in its telemetry.

Threat actors began exploiting a critical WordPress vulnerability within hours of its public disclosure. Tracked as CVE-2026-87902 (CVSS score: 9.2), the flaw lets an unauthenticated attacker achieve remote code execution (RCE) under specific server and theme conditions. 

The first attempt was logged on September 22, 2026, at 11:49 a.m. UTC, the same day patches were released.

How CVE-2026-87902 Enables Remote Code Execution

According to the WordPress advisory, an unauthenticated attacker can manipulate page-template resolution in get_page_template() so it includes a chosen, readable local .php file from outside the active theme directories.

Two preconditions apply for this vulnerability:

  • The active child or parent theme must contain a top-level directory whose name starts with page- (for example, page-templates). 
  • A local .php target file must also exist on the server and be readable by the web server account, such as pearcmd.php.
Previdian and Patchstack Confirm Active Exploitation

Previdian reported exploitation attempts against its honeypot network, and its telemetry recorded 68 exploitation attempts from a U.S.- and an Indonesia-based IP. 

Patchstack corroborated the findings and warned that requests had expanded from reconnaissance to active exploitation that writes PHP files to disk.

Which WordPress Versions to Install Now

"We're likely to see mass-exploitation attempts, but relatively few actual compromises," Previdian founder and CEO Ryan Dewhurst has said. While the platform has auto-updates enabled by default, WordPress administrators should:

  • Immediately apply version:
    • 7.1.2, 
    • 7.0.6,
    • 6.9.9, 
    • or 6.8.10, 
  • Then audit their sites for malicious activity.

A July report warned that an unauthenticated WordPress Exploit, Wp2shell, needed no login or plugins, while an “essential plugin” backdoor that was disseminated to over 20,000 active WordPress installations was flagged in April.

Explore More

Most Popular

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1WordPress-Lücke nur Stunden nach Patch attackiert013.4525-09-2026
2Уязвимости в LXD, Incus, GitLab, Radicle, ядре Linux, WordPress, OpenVPN, Flatpak, NTFS-3G, FreeRDP, CUPS, Dovecot012.4927-09-2026
3Cloudflare Fixes Cross-Tenant Data Exposure Bug in Containers011.4825-09-2026
4Revolut breach exposes authentication-authorization gap018.8617-09-2026
5Elsevier LAPSUS$ Redirect Attack: Visitors Sent to Leak Page Instead of Journals010.8124-09-2026
6Jetzt updaten! Attacken auf Roundcube-Webmail-Instanzen beobachtet014.7625-09-2026
7В Воронежской области пять часов действовал режим угрозы атаки БПЛА09.627-09-2026
8Bitget 被盗走价值 3.875 亿美元加密货币031.1327-09-2026
9MacSync macOS Stealer Returns With Binary Payloads and iCloud Tricks01325-09-2026
10FreeBSD-EN-26:21.openssl010025-08-2026

Классификация: . Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 13.59. Источник: www.technadu.com.