WordPress CVE-2026-87902: an Unauthenticated Path Traversal That Escalates into Remote Code Execution
WordPress CVE-2026-87902: an unauthenticated path traversal that escalates into remote code execution Opening A critical WordPress core vulnerability began attracting exploitation attempts within days of its disclosure, and the pattern is unusually consistent for an early campaign. CVE-2026-87902 is a path traversal issue in the template resolution logic of WordPress core, rated 9.2 on the CVSS scale. It requires no authentication and no user interaction. Public reporting attributes the first confirmed exploitation attempt to 22 September 2026 at 11:49 UTC, with 68 distinct attempts recorded b
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in