CyberNotableSingle-sourceDeveloping
4.8
WordPress Click2Shell CSRF flaw allows PHP execution; PoC published
BleepingComputerLO·3 days ago
A critical path traversal vulnerability in WordPress, CVE-2026-87902, is being actively exploited by remote, unauthenticated attackers to execute arbitrary code immediately after public disclosure. The rapid exploitation suggests threat actors are automating weaponization, increasing risk to unpatched sites. This underscores the urgency for WordPress administrators to apply patches and monitor for indicators of compromise.