Vulnerabilities · InfosecFeed Brief

Hackers start exploiting critical WordPress flaw for code execution

What you need to know

Threat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to exploiting the flaw to write files to disk that execute shell commands when accessed. [...]

Source transparency

This is an InfosecFeed curated brief based on reporting from BleepingComputer. InfosecFeed does not claim ownership of the original reporting.

Read the original report at BleepingComputer ↗