Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
WordPress Security Flaw CVE-2026-87902 Under Attack

WordPress Security Flaw CVE-2026-87902 Under Attack

Posted on September 24, 2026 By CWS

In a swift reaction to a disclosed vulnerability, attackers have started exploiting a serious flaw in WordPress, identified as CVE-2026-87902, which was made public just hours before. This security issue is rated with a CVSS score of 9.2, highlighting its critical nature, and it enables unauthorized actors to execute remote code.

Understanding the CVE-2026-87902 Vulnerability

The flaw, according to a WordPress advisory, allows an unauthenticated user to manipulate the get_page_template() function to incorporate a specific local .php file outside the active theme directories. This scenario could potentially lead to remote code execution if particular preconditions related to the server environment and the theme are satisfied. These conditions include the presence of a directory name beginning with ‘page-‘ within the active theme and a readable local .php file on the server.

Exploitation Attempts and Recorded Activity

Previdian, a cybersecurity firm, reported observing exploitation efforts targeting this vulnerability through its honeypot network. These attempts, originating from an IP in New Jersey, involve malicious requests that interact with the local PHP file pearcmd.php and execute scripts from GitHub. Although the vulnerability is severe, the specific conditions required for exploitation may limit its impact. However, with WordPress’s default setting of automatic updates, the potential for widespread exploitation attempts remains.

Data from Previdian indicates 68 exploitation attempts as of September 23, 2026, with some originating from IP addresses in Indonesia. Patchstack, a WordPress security company, confirmed these findings, noting a shift from reconnaissance activities to actual exploitation involving PHP file manipulations.

Impact and Recommendations for WordPress Users

The initial exploitation was logged on September 22, 2026, coinciding with the release of patches for the vulnerability. Exploitation activities involve writing attacker-controlled PHP content to temporary directories, using filenames like wp-pear-rce-flag.php, poc87902.php, among others. Several IP addresses associated with these attacks have been identified, suggesting a coordinated effort to exploit this vulnerability.

In response to these active threats, WordPress administrators are strongly advised to update their installations to version 7.1.2 or applicable versions like 7.0.6, 6.9.9, or 6.8.10. Conducting thorough audits for any signs of compromise is also recommended to mitigate potential risks associated with this vulnerability.

The Hacker News Tags:auto-updates, CVE-2026-87902, Cybersecurity, Exploit, Honeypot, Patchstack, PHP, Previdian, RCE, remote code execution, Security, Vulnerability, web security, website security, WordPress

Post navigation

Previous Post: AI-Powered Android Trojan Targets Banking Apps
Next Post: Agentic Remediation: Closing the Loop in Cybersecurity

Related Posts

APT28 Deploys BEARDSHELL and COVENANT in Ukraine Espionage APT28 Deploys BEARDSHELL and COVENANT in Ukraine Espionage The Hacker News
Apple Warns French Users of Fourth Spyware Campaign in 2025, CERT-FR Confirms Apple Warns French Users of Fourth Spyware Campaign in 2025, CERT-FR Confirms The Hacker News
Preparing for Quantum Security: A Crucial Webinar Preparing for Quantum Security: A Crucial Webinar The Hacker News
Critical Security Threats and Global Cyber Developments Critical Security Threats and Global Cyber Developments The Hacker News
Hugging Face Diffusers Security Flaws Threaten AI Systems Hugging Face Diffusers Security Flaws Threaten AI Systems The Hacker News
Chinese Cybercrime Group Runs Global SEO Fraud Ring Using Compromised IIS Servers Chinese Cybercrime Group Runs Global SEO Fraud Ring Using Compromised IIS Servers The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI Agents Exploit Websites for Data Collection Concerns
  • Ukrainian Sites Hacked for Psychedelic Stealer Distribution
  • Konni Malware Campaign Targets Ukrainian Entities with Fake PDFs
  • Agentic Remediation: Closing the Loop in Cybersecurity
  • WordPress Security Flaw CVE-2026-87902 Under Attack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI Agents Exploit Websites for Data Collection Concerns
  • Ukrainian Sites Hacked for Psychedelic Stealer Distribution
  • Konni Malware Campaign Targets Ukrainian Entities with Fake PDFs
  • Agentic Remediation: Closing the Loop in Cybersecurity
  • WordPress Security Flaw CVE-2026-87902 Under Attack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark