Skip to main content
CyberSingle-sourceHighDevelopingFeatured
7.1

WordPress CVE-2026-87902 Path Traversal Exploited Within Hours of Disclosure

A critical path traversal vulnerability in WordPress, CVE-2026-87902, is being actively exploited by remote, unauthenticated attackers to execute arbitrary code immediately after public disclosure. The rapid exploitation suggests threat actors are automating weaponization, increasing risk to unpatched sites. This underscores the urgency for WordPress administrators to apply patches and monitor for indicators of compromise.

SecurityWeekabout 9 hours agoengCredibility 26%View source

Score Breakdown

Mosaic Score7.1
Confidence0.7
Significance0.8
Source credibility0.3
Source

Related signals

8 found