Hackers Are Targeting a Critical WordPress Flaw, So Be on Your Guard


  • WordPress Core Flaw CVE-2026-87902 (Path Traversal, Severity 8.1) Allows PHP File Inclusion and Possible RCE
  • Patch released in v7.1.2 and backported to 4.7+; The exploitation began within hours and is now widespread.
  • Administrators need to update urgently; Interim mitigations include blocking sequence traversals and disabling risky ARP/PHP configurations.

Researchers say hackers are actively exploiting a high-severity vulnerability in WordPress that can lead to a complete takeover of the website. A patch is available and WordPress users are urged to update immediately or risk losing access to their assets.

Discovered by security researcher Robert Ressl, the vulnerability in question is tracked as CVE-2026-87902. It is an unauthenticated path traversal bug 8.1/10 (high severity) affecting WordPress Core. According to WordPress itself, as well as the National Vulnerability Database, the bug can lead to the inclusion of local PHP files and, in certain scenarios, remote code execution (RCE).

Avatar photo

Miraj Islam is a writer and contributor at Oalanbrado, interested in news, current events, technology, lifestyle, and stories that matter to readers. He enjoys researching different topics and turning information into clear, useful, and engaging articles. Through his work, Miraj aims to keep readers informed with fresh perspectives and easy-to-understand content from Brazil and around the world.

Post Comment