Hackers start exploiting critical WordPress flaw for code execution
Threat actors have moved from probing vulnerable WordPress sites to actively exploiting CVE-2026-87902 to execute shell commands.

Cybersecurity observers report a dangerous escalation in attacks targeting WordPress websites, as threat actors begin actively exploiting a critical vulnerability tracked as CVE-2026-87902.
According to BleepingComputer, while attackers initially spent time probing websites to identify vulnerable targets, they have now shifted to active exploitation. The flaw allows them to write specific files to the server disk that execute shell commands when accessed.
This type of Remote Code Execution vulnerability poses severe risks to web administrators, potentially granting unauthorized users deep access to the underlying server infrastructure and compromising sensitive data.
For tech professionals, developers, and website owners, this incident underscores the critical importance of maintaining up-to-date web infrastructure and applying security patches immediately upon release.
Security experts advise conducting swift audits of all WordPress installations, monitoring server logs for suspicious file creation, and ensuring that all plugins and core components are updated to the latest secure versions.



