Attackers have shifted from probing CVE-2026-87902 to exploiting it on WordPress sites, using the flaw to write PHP files to disk that can execute shell commands when accessed. WordPress 7.1.2 fixes the critical issue, and administrators should update immediately and review logs for signs of malicious activity. #WordPress #CVE-2026-87902 #Patchstack
Keypoints
- Attackers began probing vulnerable WordPress sites less than five hours after the patch was released.
- The activity has escalated from reconnaissance to payload delivery and disk writing.
- CVE-2026-87902 is an unauthenticated path traversal flaw that can lead to RCE.
- Exploitation requires specific theme and file conditions, including readable local PHP files.
- Administrators should upgrade to WordPress 7.1.2 and block the reported source IPs.