• Login
teqpost
  • Home
  • Hardware
  • Gaming
  • Gadgets
  • AI
  • Software
  • Security
  • Policy
No Result
View All Result
teqpost
  • Home
  • Hardware
  • Gaming
  • Gadgets
  • AI
  • Software
  • Security
  • Policy
No Result
View All Result
teqpost
No Result
View All Result

Home / Security / WordPress patches critical vulnerability under active attack

WordPress patches critical vulnerability under active attack

byLotfi Ben Taleb
September 24, 2026
in Security
Reading Time: 2 mins read
3D-rendered black server rack unit labeled 'Kaze Servers' with status displays reading operational or stall
Share on Facebook
Share on Twitter

WordPress has patched a critical vulnerability, CVE-2026-87902, that lets an attacker with no account on a site force it to load a PHP file from outside the theme folder, and on some server configurations that escalates to full code execution. The fix for this WordPress critical vulnerability shipped on 22 September in WordPress 7.1.2, backported to every branch the project still supports, back to version 4.7. That reach, covering release lines going back nine years, is the tell: the bug lives in WordPress core rather than a plugin or theme, so every unpatched install carries the same exposure regardless of age.

How the WordPress critical vulnerability works

CVE-2026-87902 is a file-inclusion bug. It lets an unauthenticated request tell WordPress to load and execute a PHP file that lives outside the theme directory it should be confined to. On a typical shared host that alone can expose site internals or feed a chain toward further compromise.

On servers where an attacker can also get a file onto disk, through a separate upload path, a writable temp directory, or a misconfigured filesystem, the same inclusion bug becomes full code execution: WordPress ends up running a file the attacker planted, with whatever privileges the web server process holds. That second step is why the advisory calls the impact server-dependent rather than universal, and why the fix went out to every supported branch rather than just the current one.

Exploitation is no longer theoretical

The gap between disclosure and attack was short. Threat actors scanning for CVE-2026-87902 have moved on to actively exploiting it, using the flaw to write files to disk that execute shell commands when accessed, BleepingComputer reports. That detail matters more than the flaw’s existence: a web shell dropped this way survives a WordPress update unless it is found and removed separately.

By our arithmetic, that shift happened fast: teqpost calculates roughly 24.5 hours separated the first report of the patch from the first confirmed report of exploitation in the wild. That is not much runway for a site owner running an affected branch to patch before the flaw was weaponised, and it argues against treating “we’ll update this weekend” as a safe plan for any internet-facing WordPress install.

This is a pattern teqpost has tracked through September: on 19 September we covered an unauthenticated RCE in Orkes Conductor already under active attack, on a similarly compressed timeline between disclosure and exploitation. CVE-2026-87902 repeats that timeline in software with a vastly larger installed base, which is what makes the short exploitation window here the more consequential story.

What to watch

  • Any WordPress core install not yet on 7.1.2, or the equivalent patched point release for its branch back to 4.7, remains exposed.
  • Managed-hosting customers should confirm the update actually applied rather than assume an automatic background update caught it.
  • Self-hosted sites should check for PHP files that do not belong in the theme directory, the artefact BleepingComputer’s reporting points to as a sign of compromise, since a plain version update does not remove a shell already dropped on disk.

Image: Spellkaze via Openverse, licensed under CC BY 4.0.

Tags: vulnerability
Previous Post

Memory makers plan 4GB and 6GB GDDR7 chips for 2027 and 2028

Next Post

Surface Mouse gets haptic feedback and an action button

Related Posts

Tangled colored network patch cables running into a server rack panel
Security

Citrix confirms two NetScaler zero-days under active attack

September 28, 2026
Rows of blue-lit server hard drive caddies in a data center rack
Security

ShinyHunters bypass WAFs to exploit Oracle PeopleSoft flaw

September 27, 2026
Rendered illustration of a data center corridor lined with server racks showing blue status lights
Security

WSO2 and Adobe Commerce flaws land on CISA’s exploited list

September 26, 2026
0 0 votes
Article Rating
Subscribe
Notify of
0 Comments

Popular News

Three Samsung phone backs side by side, green with many cameras, purple and cream with three cameras

Galaxy S27 renders show a design split from the Ultra

September 28, 2026
Close-up of an iPhone's glass back and dual rear camera lenses lit from above

iPhone Duo 3D model lets you open the hinge before launch

September 20, 2026
A Radeon graphics card installed in a PC case, lit by green and blue ambient light

Modders get DLSS 5 running on AMD’s RDNA 4 GPUs

September 7, 2026
Close-up of a GeForce RTX graphics card installed in a PC case with a blurred power cable bundle

DLSS 5 mods expose RTX 5090’s power connector limit

September 27, 2026
Next Post
Microsoft Arc Mouse folding wireless mouse beside its USB nano receiver on white background

Surface Mouse gets haptic feedback and an action button

Technology for enthusiasts and gamers. Hardware, gaming and the software in between, with the spec sheets read properly and the marketing taken back out.

Categories

Categories

  • AI
  • Gadgets
  • Gaming
  • Hardware
  • Policy
  • Security
  • Software
Site Links
  • Latest
  • About
  • Contact
About
  • How We Work
  • Privacy Policy

© 2026 teqpost. All rights reserved.

  • Privacy Policy
  • Contact

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Hardware
  • Gaming
  • Gadgets
  • AI
  • Software
  • Security
  • Policy

© 2026 JNews - Premium WordPress news & magazine theme by Jegtheme.

wpDiscuz
0
0
Would love your thoughts, please comment.x
()
x
| Reply