Hackers start exploiting critical WordPress flaw for code execution
Summary
Threat actors are actively exploiting a critical vulnerability in WordPress, identified as CVE-2026-87902. Attackers have progressed from scanning for vulnerable sites to executing code on compromised systems by writing files that trigger shell commands upon access.
IFF Assessment
FOE
The active exploitation of a critical vulnerability allows attackers to gain code execution, posing a direct threat to WordPress sites and their administrators.
Severity
8.1
High
Defender Context
This highlights the immediate danger posed by known, exploitable vulnerabilities in widely used platforms like WordPress. Defenders should prioritize patching or implementing mitigating controls for CVE-2026-87902 immediately, and maintain vigilance for signs of exploitation on their systems.