Hackers exploited a critical WordPress flaw within hours of the patch
Attackers began exploiting a critical WordPress flaw within hours of the fix. The bug, CVE-2026-87902, can let an attacker with no login run code on a website’s server. It only works under certain conditions. WordPress fixed the flaw in version 7.1.2 on 22 September. It also patched every older…
Sources
Vulnerabilities
Why this score
| Signal | Points |
|---|---|
| kev added | 50 |
| kev short fuse — 3 days to remediate | 15 |
| ssvc active | 35 |
| epss high | 20 |
| public poc — 21 repositories | 20 |
| widely deployed | 15 |