Hackers start exploiting critical WordPress flaw for code execution

Threat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to exploiting the flaw to write files to disk that execute shell commands when accessed. [...]

security

Sources

Vulnerabilities

Why this score
Signals contributing to the severity score
SignalPoints
widely deployed15