Back to all news
Security

Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure

The Hacker News·September 24, 2026·1 min read
Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure

Threat actors are actively exploiting a critical WordPress vulnerability, CVE-2026-87902 (CVSS 9.2), within hours of disclosure. The flaw allows unauthenticated attackers to achieve remote code execution by manipulating get_page_template() to include a chosen readable local .php file. Immediate patching is urged as attacks are already underway.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store