CyberHighReportedAccelerating
7.1
WordPress CVE-2026-87902 Path Traversal Exploited Within Hours of Disclosure
SecurityWeekLO·3 days ago
A CSRF vulnerability in the Elementor plugin for WordPress could let unauthenticated attackers create admin accounts, potentially leading to full site compromise. The flaw is in a widely used plugin, increasing the attack surface. No active exploitation has been confirmed yet, but the risk is significant given Elementor's large install base.