vulnerability
Critical WordPress Vulnerability Exploited Immediately After Disclosure
HighCVSS 8.1KEVEPSS 20%
Summary
A critical WordPress vulnerability (CVE-2026-87902) was exploited within hours of its disclosure, leading to active compromises. The vulnerability stems from a path traversal flaw in WordPress’ page-template resolution, allowing unauthenticated attackers to execute code.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data