Threat actors have begun actively exploiting CVE-2026-87902, a critical WordPress vulnerability allowing unauthenticated remote code execution through path traversal. After initial reconnaissance probes following the patch release on September 22, malicious activity increased tenfold as attackers progressed to writing executable files to disk. WordPress 7.1.2 addresses the flaw across all supported versions.
cPanel disclosed three security flaws, including a critical vulnerability in its CalDAV/CardDAV service that allows any hosting account holder to execute code as root and gain full server control. A second flaw in the WP Toolkit plugin enables users to modify databases belonging to other accounts, while a third permits reading other accounts' calendar data. cPanel has released patched versions for all three issues.
A critical unauthenticated path traversal vulnerability (CVSS 9.2) affects all WordPress versions since 2016, allowing attackers to include arbitrary PHP files and potentially execute code if specific theme and server conditions are met. WordPress 7.1.2 patches the issue, with fixes backported to all versions from 4.7 onward.