WordPress CVE-2026-87902 now exploited for code execution
Attackers have moved beyond scanning for WordPress sites vulnerable to CVE-2026-87902. They are now exploiting the flaw to plant files that run shell commands when they are accessed, according to WordPress security firm Patchstack.
The vulnerability was fixed in WordPress 7.1.2. Scanning began less than five hours after that release. Since then, malicious traffic has grown tenfold, and attackers are now trying to deliver payloads.
Patchstack says it saw the first malicious requests at 17:44 UTC on September 22. They came from a small group of IP addresses and targeted several sites under the company's protection.
A path traversal bug with a critical rating
Sponsored Recommended for you – discover more →
