The critical WordPress vulnerability CVE-2026-87902 is being actively exploited, with activity progressing from reconnaissance to attempts to write malicious PHP files on vulnerable servers. The flaw affects WordPress Core versions 4.7.0 through 7.1.1 and has been fixed in WordPress 7.1.2 and backported releases. Patchstack researchers reported that exploitation began on September 22, shortly after the security update was released. Initial requests targeted harmless WordPress core files to determine whether sites were vulnerable. Within a day, attackers began targeting PEAR’s pearcmd.php utility to create PHP files in temporary directories. This technique can lead to remote code execution. CVE-2026-87902 is an unauthenticated...
Läs hela artikeln hos källan.
Kommentarer (0)
Inga kommentarer ännu. Bli först med att kommentera!