$ techbeacon▋
CVE & Exploits

Critical WordPress Flaw Exploited Within Hours of Public Disclosure

Critical WordPress Flaw Exploited Within Hours of Public Disclosure

Security researchers have observed active exploitation of a newly disclosed WordPress vulnerability, CVE-2026-87902, within a matter of hours after its public announcement. The flaw, assigned a CVSS score of 9.2, enables unauthenticated attackers to execute arbitrary code on vulnerable servers, raising immediate concerns for the millions of sites that rely on the platform.

The vulnerability stems from improper handling of user‑supplied input in a core WordPress component, allowing malicious actors to inject code that runs with the privileges of the web server. Because the attack does not require prior authentication, even sites that have not been actively targeted can become compromised if they run an unpatched version of the software.

WordPress powers an estimated 40% of all websites worldwide, making it a frequent target for cyber‑crime groups. Historically, high‑severity bugs in the platform have prompted rapid patch cycles, but the speed at which this particular issue is being weaponised underscores the growing efficiency of threat actors who monitor vulnerability disclosures closely. Past incidents, such as the 2020 REST API exposure and the 2022 XML-RPC bypass, illustrate how quickly attackers can translate a disclosed flaw into a live exploit.

Following the disclosure, the WordPress security team issued an emergency advisory and released a patch that addresses the input‑validation weakness. The advisory advises site administrators to apply the update immediately, enable automatic updates where possible, and review server logs for signs of suspicious activity. Security firms monitoring the threat landscape have also released indicators of compromise to aid in detection.

Experts warn that the window between disclosure and exploitation is shrinking, emphasizing the importance of proactive maintenance. Organizations are urged to audit their WordPress installations, verify that all plugins and themes are up to date, and consider additional hardening measures such as web‑application firewalls. The rapid exploitation of CVE-2026-87902 serves as a reminder that timely patching remains one of the most effective defenses against emerging cyber threats.

Arjun Pratap Rana — Arjun reports on data breaches and corporate security incidents, focusing on how leaks happen and what they mean for affected users. Verifies claims against HaveIBeenPwned and leak listings.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related