HackerFeeds

CyberSecurity News

Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure

The Hacker News
· September 24, 2026

AI summary

Threat actors are exploiting a critical WordPress security flaw shortly after its public disclosure. The vulnerability, identified as CVE-2026-87902, has a CVSS score of 9.2 and could allow an unauthenticated attacker to achieve remote code execution. This flaw enables an attacker to make the get_page_template function include a chosen local .php file, potentially leading to malicious activity. The rapid exploitation of this vulnerability by threat actors highlights its severity and potential impact.

Vulnerabilities mentioned

Read the full article at The Hacker Newsthehackernews.com/2026/09/attackers-exploit-wordpress-cve-2026.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.