Hackers exploited a critical WordPress flaw within hours of the patch

Attackers began exploiting a critical WordPress flaw within hours of the fix. The bug, CVE-2026-87902, can let an attacker with no login run code on a website’s server. It only works under certain conditions. WordPress fixed the flaw in version 7.1.2 on 22 September. It also patched every older…

releasessecurity

Sources

Vulnerabilities

Why this score
Signals contributing to the severity score
SignalPoints
kev added50
kev short fuse — 3 days to remediate15
ssvc active35
epss high20
public poc — 21 repositories20
widely deployed15