WordPress unauthenticated path traversal flaw actively exploited (CVE-2026-87902)
Vulnerability
Summary
Hide ▲
Show ▼
Attackers are actively exploiting CVE-2026-87902 in WordPress, turning an unauthenticated path traversal flaw into payload delivery and potential remote code execution on vulnerable sites. Patchstack saw the first malicious requests at 17:44 UTC on September 22, less than five hours after WordPress 7.1.2 shipped. The activity escalated from reconnaissance to file writes under /tmp and /var/tmp, including names such as wp-pear-rce-flag.php and poc87902.php.
Related Happenings
WooCommerce Wholesale Lead Capture CVE-2026-27540 exploitation wave
Exploitation Wave
H score16
First: 15.09.2026 17:45
Last: 15.09.2026 17:45
Sources 1
About this happening:
CVE-2026-27540 exploitation against WooCommerce Wholesale Lead Capture is driving repeated spikes and more than 100,000 blocked attacks, putting WordPress sites at ris...
WooCommerce Wholesale Lead Capture CVE-2026-27540 exploitation wave
Exploitation WaveAbout this happening: CVE-2026-27540 exploitation against WooCommerce Wholesale Lead Capture is driving repeated spikes and more than 100,000 blocked attacks, putting WordPress sites at ris...
CPanel & WHM authentication-bypass exploitation wave (CVE-2026-41940)
Exploitation Wave
H score89
First: 04.05.2026 11:25
Last: 04.05.2026 11:25
Sources 1
About this happening:
CVE-2026-41940 is being exploited in a large cPanel & WHM compromise wave, with attackers using compromised GitHub repositories as distributed attack infrastructure. T...
CPanel & WHM authentication-bypass exploitation wave (CVE-2026-41940)
Exploitation WaveAbout this happening: CVE-2026-41940 is being exploited in a large cPanel & WHM compromise wave, with attackers using compromised GitHub repositories as distributed attack infrastructure. T...
EssentialPlugin package hit by network compromise
Incident
H score25
First: 15.04.2026 23:33
Last: 15.04.2026 23:33
Sources 1
About this happening:
The EssentialPlugin WordPress package was compromised with a backdoor, enabling unauthorized access to websites running its plugins and putting hundreds of thousands...
EssentialPlugin package hit by network compromise
IncidentAbout this happening: The EssentialPlugin WordPress package was compromised with a backdoor, enabling unauthorized access to websites running its plugins and putting hundreds of thousands...
Timeline
-
23.09.2026 21:31 2 articles · 2h ago
WordPress unauthenticated path traversal flaw actively exploited (CVE-2026-87902)
Initial DisclosureEarly activity against WordPress CVE-2026-87902 was reconnaissance, with attackers testing whether target sites exposed reachable file paths. The pattern then advanced into payload delivery once vulnerable targets were identified.
Show sources
- Hackers start exploiting critical WordPress flaw for code execution — www.bleepingcomputer.com — 23.09.2026 21:31
- Hackers start exploiting critical WordPress flaw for code execution — www.bleepingcomputer.com — 23.09.2026 21:31