Threat actors have begun actively exploiting CVE-2026-87902, a critical WordPress vulnerability that allows unauthenticated remote code execution through path traversal. Malicious activity increased tenfold within days of the patch release, with attackers now writing executable files to disk. WordPress addressed the flaw in version 7.1.2 and backported fixes to all supported versions.