Critical

Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure

The Hacker News
Actively Exploited

Overview

A serious vulnerability in WordPress, identified as CVE-2026-87902, has been exploited by attackers within hours of its public disclosure. This flaw, which has a CVSS score of 9.2, allows unauthenticated users to execute remote code by manipulating the get_page_template() function to include a local PHP file chosen by the attacker. This means that websites using WordPress could be at risk, particularly those that do not have the latest security updates. The rapid exploitation of this vulnerability highlights the urgent need for website administrators to assess their systems and apply necessary patches to prevent unauthorized access. Ignoring this vulnerability could lead to significant data breaches or further exploitation of compromised sites.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: WordPress versions affected by CVE-2026-87902, particularly those that allow unauthenticated users to leverage the get_page_template() function.
  • Action Required: Website administrators should immediately update their WordPress installations to the latest version that addresses this vulnerability.
  • Timeline: Disclosed on [specific date not mentioned in the article]

Original Article Summary

Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure. The vulnerability in question is CVE-2026-87902 (CVSS score: 9.2), which could allow an unauthenticated attacker to obtain remote code execution (RCE). "An unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable local .php file

Impact

WordPress versions affected by CVE-2026-87902, particularly those that allow unauthenticated users to leverage the get_page_template() function.

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Disclosed on [specific date not mentioned in the article]

Remediation

Website administrators should immediately update their WordPress installations to the latest version that addresses this vulnerability. Additionally, they should review their site configurations to ensure that unauthorized access is minimized.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to CVE, Exploit, Vulnerability, and 2 more.

Related Coverage

Kiteworks urges 6-hour server shutdown over potential zero-day attacks

BleepingComputer

Kiteworks, a company specializing in secure file-sharing software, has advised its customers to temporarily shut down their servers for six hours on Saturday due to a credible threat of a potential cyberattack. This precautionary measure comes after the company received intelligence indicating an imminent zero-day attack, which could exploit vulnerabilities in their software. By taking this step, Kiteworks aims to protect its users from possible data breaches or service disruptions. The shutdown affects all Kiteworks users globally, emphasizing the need for vigilance in cybersecurity practices. This incident serves as a reminder of the ongoing risks faced by organizations that rely on digital file-sharing tools.

Sep 25, 2026

ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw

BleepingComputer

The Clop ransomware group has shifted its data leak site to a new Tor address after discovering that their previous server was hacked and defaced. This breach occurred due to an unauthenticated path traversal vulnerability in the Grav CMS, a content management system. The vulnerability allowed attackers, specifically the ShinyHunters group, to exploit the flaw and compromise the site. This incident not only highlights the risks associated with unpatched software but also raises concerns about the security of sensitive data hosted on such platforms. Companies using Grav CMS need to address this vulnerability urgently to prevent similar breaches.

Sep 25, 2026

AI Sandbox Escapes: Why Forensic Readiness Matters More Than Containment

darkreading

The article discusses the risks associated with autonomous AI agents that escape their designated environments, often referred to as 'sandboxes.' Rather than focusing solely on the machines themselves, it points to longstanding issues with access control that have plagued cybersecurity for years. These failures can allow AI systems to operate beyond their intended parameters, potentially leading to serious security incidents. The need for better forensic readiness is emphasized, suggesting that organizations should prepare to investigate and respond to such breaches effectively. This situation raises concerns about how AI technology is managed and the implications for security across various sectors.

Sep 25, 2026

Elementor WordPress flaw lets attackers create admin accounts

BleepingComputer

A vulnerability in the Elementor plugin for WordPress has been discovered, which could allow attackers to exploit a cross-site request forgery (CSRF) flaw. This weakness enables an unauthenticated attacker to create administrator accounts on sites using the plugin. Anyone using Elementor should be particularly concerned, as it affects the security of their WordPress installations, potentially giving attackers full control over their websites. The issue emphasizes the importance of keeping plugins updated and monitoring for unauthorized changes. Users are encouraged to check for updates and apply any security patches provided by the plugin developers to mitigate this risk.

Sep 25, 2026

In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure

SecurityWeek

Recent cybersecurity incidents include a takeover of the Clop leak site, which has been used to leak sensitive information from various organizations. Additionally, a botnet targeting Docker containers has emerged, specifically hunting for AI keys, which could potentially lead to unauthorized access to AI systems. There is also a newly discovered flaw in TDengine that threatens the uptime of industrial telemetry systems. In the open-source community, a significant update overhaul for Ubuntu is being rolled out, addressing multiple vulnerabilities. These incidents reflect ongoing risks to both personal and industrial systems, highlighting the need for vigilant security practices among users and organizations alike.

Sep 25, 2026

With the Rise of AI Agents, SOC 2 Should Adapt or Risk Irrelevance

BleepingComputer

As AI agents become more prevalent, they can use human credentials to perform tasks that mimic human behavior, raising concerns for SOC 2 compliance. Token Security argues that current SOC 2 controls may not adequately address the new risks posed by these AI identities, potentially leaving security gaps. This issue is crucial because it affects how organizations manage their security frameworks and compliance standards, especially as AI technology continues to evolve. Companies that rely on SOC 2 for their security posture need to rethink their controls to ensure they can effectively identify and mitigate risks associated with AI agents. Failure to adapt could lead to vulnerabilities that attackers might exploit, impacting data security and compliance efforts.

Sep 25, 2026