Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Hackers start exploiting critical WordPress flaw for code execution

    September 24, 2026

    oh my god

    September 24, 2026

    Check Point warns of hackers exploiting Security Gateway VPN RCE flaw

    September 23, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»Hackers start exploiting critical WordPress flaw for code execution
    News

    Hackers start exploiting critical WordPress flaw for code execution

    adminBy adminSeptember 24, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Hackers start exploiting critical WordPress flaw for code execution

    Threat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to exploiting the flaw to write files to disk that execute shell commands when accessed.

    Initial attack traffic was only for reconnaissance and started less than five hours after the patch was released in WordPress 7.1.2. Malicious activity increased by ten times, and attackers are now trying to deliver payloads.

    WordPress security firm Patchstack reports that it observed the first malicious requests at 17:44 UTC on September 22 from a small group of IP addresses targeting multiple sites under its protection.

    Discovered by security researcher Robert Ressl, the issue is an unauthenticated path traversal bug that can lead to remote code execution (RCE) under certain conditions.

    The WordPress security team assesses that CVE-2026-87902 has critical severity, assigning a score of 9.2 out of 10.

    “An unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable local .php file outside the active theme directories,” reads the official advisory.

    For RCE to be possible, the following conditions are required:

    • Active parent or child theme must have a top-level directory with a name starting with page-, such as page-templates. The attacker must also target a local .PHP file that exists and is readable by the web server
    • The included file must be readable by the web server account. The advisory gives pearcmd.php as an example when PHP’s register_argc_argv setting is active.

    The WordPress advisory notes that the official PHP image for Docker is affected, and so is the default cPanel configuration when a PHP version before 8.5 is used.

    WordPress addressed CVE-2026-87902 yesterday with the release of version 7.1.2, and fixes have also been backported to all branches down to 4.7 because of the critical severity of the flaw. Releases before 4.6 will not be getting a fix for this flaw.

    Patchstack reports that in the observed reconnaissance activity, the attackers attempted to include ordinary WordPress core files, apparently to identify vulnerable sites.

    Starting today, the researchers noticed that traffic related to the vulnerability increased tenfold and includes a writing to disk stage.

    “The third stage swaps config-show for config-create, which pearcmd will happily use to write a file wherever it is told, with content the attacker controls.”

    Some of the payloads only write a string that marks the host as exploitable via CVE-2026-87902. However, the researchers also saw payloads that “write a short tag that executes a shell command on access,” which indicates malicious activity.

    The files are delivered to /tmp and /var/tmp and have names like wp-pear-rce-flag.php, poc87902.php, luci_.php, and zeta_.php.

    Although the security firm did not publish a working request example, it warned that the observed probes use double-encoded traversal sequences in ‘pagename’ alongside a valid ‘page_id.’

    The source IPs that should be added to a blocklist are 169.58.48.193, 169.58.48.195, and 2001:df1:e8c0::106b.

    Given the active exploitation of CVE-2026-87902, website administrators should update to WordPress version 7.1.2 as soon as possible and review the logs for malicious activity.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous Articleoh my god
    admin
    • Website

    Related Posts

    News

    Check Point warns of hackers exploiting Security Gateway VPN RCE flaw

    September 23, 2026
    News

    New RemControl Android banking malware targets users in Europe and Canada

    September 23, 2026
    News

    Placeholder domain used in dev docs now serves ClickFix attacks

    September 23, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202679 Views

    How fraudsters target credit unions

    May 4, 202644 Views

    IP Address Investigations and Local OSINT

    March 20, 202642 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202679 Views

    How fraudsters target credit unions

    May 4, 202644 Views

    IP Address Investigations and Local OSINT

    March 20, 202642 Views
    Our Picks

    Hackers start exploiting critical WordPress flaw for code execution

    September 24, 2026

    oh my god

    September 24, 2026

    Check Point warns of hackers exploiting Security Gateway VPN RCE flaw

    September 23, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.