Threat actors are actively exploiting WordPress CVE-2026-87902, a critical remote code execution vulnerability, within hours of its public disclosure. The attacks target servers meeting specific preconditions and use local PHP files like pearcmd.php to execute malicious code, with over 68 exploitation attempts recorded from multiple countries since September 22, 2026.