WordPress patched a critical vulnerability (CVE-2026-87902, CVSS 9.2) affecting versions 4.7.0 through 7.1.1 that allows unauthenticated attackers to load external PHP files, potentially enabling code execution on some servers. The fix shipped September 22 across all supported branches, and site owners are urged to update immediately as no workaround exists.
Threat actors have begun actively exploiting CVE-2026-87902, a critical WordPress vulnerability allowing unauthenticated remote code execution through path traversal. After initial reconnaissance probes following the patch release on September 22, malicious activity increased tenfold as attackers progressed to writing executable files to disk. WordPress 7.1.2 addresses the flaw across all supported versions.
Threat actors have begun actively exploiting CVE-2026-87902, a critical WordPress vulnerability that allows unauthenticated remote code execution through path traversal. Malicious activity increased tenfold within days of the patch release, with attackers now writing executable files to disk. WordPress addressed the flaw in version 7.1.2 and backported fixes to all supported versions.