Find notable cyber news and cases, enriched with sources, timelines, and signals.

WordPress unauthenticated path traversal flaw actively exploited (CVE-2026-87902)

Vulnerability
First reported
Last updated
Happening score
H score 44
1 unique sources, 1 articles

Summary

Hide ▲

Attackers are actively exploiting CVE-2026-87902 in WordPress, turning an unauthenticated path traversal flaw into payload delivery and potential remote code execution on vulnerable sites. Patchstack saw the first malicious requests at 17:44 UTC on September 22, less than five hours after WordPress 7.1.2 shipped. The activity escalated from reconnaissance to file writes under /tmp and /var/tmp, including names such as wp-pear-rce-flag.php and poc87902.php.

Related Happenings

WooCommerce Wholesale Lead Capture CVE-2026-27540 exploitation wave

Exploitation Wave
H score16 First: 15.09.2026 17:45 Last: 15.09.2026 17:45 Sources 1

About this happening: CVE-2026-27540 exploitation against WooCommerce Wholesale Lead Capture is driving repeated spikes and more than 100,000 blocked attacks, putting WordPress sites at ris...

CPanel & WHM authentication-bypass exploitation wave (CVE-2026-41940)

Exploitation Wave
H score89 First: 04.05.2026 11:25 Last: 04.05.2026 11:25 Sources 1

About this happening: CVE-2026-41940 is being exploited in a large cPanel & WHM compromise wave, with attackers using compromised GitHub repositories as distributed attack infrastructure. T...

EssentialPlugin package hit by network compromise

Incident
H score25 First: 15.04.2026 23:33 Last: 15.04.2026 23:33 Sources 1

About this happening: The EssentialPlugin WordPress package was compromised with a backdoor, enabling unauthorized access to websites running its plugins and putting hundreds of thousands...

Timeline

  1. 23.09.2026 21:31 2 articles · 2h ago

    WordPress unauthenticated path traversal flaw actively exploited (CVE-2026-87902)

    Initial Disclosure

    Early activity against WordPress CVE-2026-87902 was reconnaissance, with attackers testing whether target sites exposed reachable file paths. The pattern then advanced into payload delivery once vulnerable targets were identified.

    Show sources