Crypto Ticker:
sysadmin from Cyber Security News

Hackers Actively Exploiting WordPress Vulnerability to Execute Malicious Code

Abinaya
4 hours ago
7 Views
0 Comments
Hackers Actively Exploiting WordPress Vulnerability to Execute Malicious Code

The critical WordPress vulnerability CVE-2026-87902 is being actively exploited, with activity progressing from reconnaissance to attempts to write malicious PHP files on vulnerable servers. The flaw affects WordPress Core versions 4.7.0 through 7.1.1 and has been fixed in WordPress 7.1.2 and backported releases. Patchstack researchers reported that exploitation began on September 22, shortly after the security update was released. Initial requests targeted harmless WordPress core files to determine whether sites were vulnerable. Within a day, attackers began targeting PEAR’s pearcmd.php utility to create PHP files in temporary directories. This technique can lead to remote code execution. CVE-2026-87902 is an unauthenticated...

Read the full article at the source.

Join the discussion — comment, vote, and submit links.

Register
Was this helpful?
Share:

Comments (0)

Please login or register to join the discussion

No comments yet. Be the first to comment!