Hackers are targeting a critical WordPress flaw, so be on your guard

https://cdn.mos.cms.futurecdn.net/7NLZKWEKmFLJVAH4nubeaX-970-80.jpg
  • WordPress Core flaw CVE‑2026‑87902 (path traversal, 8.1 severity) enables PHP file inclusion and possible RCE
  • Patch released in v7.1.2 and backported to 4.7+; exploitation began within hours, now widespread
  • Admins must urgently update; interim mitigations include blocking traversal sequences and disabling risky ARP/PHP settings

Hackers are actively exploiting a high severity vulnerability in WordPress that can lead to full website takeover, researchers are saying. A patch is available, and WordPress users are urged to upgrade immediately or risk losing access to their assets.

Discovered by security researcher Robert Ressl, the vulnerability in question is tracked as CVE-2026-87902. It is an 8.1/10 (high severity) unauthenticated path traversal flaw affecting WordPress Core. According to WordPress itself, as well as the National Vulnerability Database, the bug can lead to local PHP file inclusion and, in certain scenarios, remote code execution (RCE).

"An unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable...

Copyright of this story solely belongs to www.techradar.com. To see the full text click HERE

Read more