Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Crusoe abandons $1.25B plan to use Boom turbines at AI data centers

    September 25, 2026

    Liquid AI Releases LFM2.5-VL-3B-DSpark: Speculative Decoding for Vision-Language Models With Up to 3.13x Faster Decoding

    September 25, 2026

    F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers

    September 25, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Crusoe abandons $1.25B plan to use Boom turbines at AI data centers
    • Liquid AI Releases LFM2.5-VL-3B-DSpark: Speculative Decoding for Vision-Language Models With Up to 3.13x Faster Decoding
    • F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers
    • US Prosecutors Want $84.2 Million From a Bank Tied to Tether
    • NASA Welcomes San Marino Signing the Artemis Accords  
    • Climate Crisis Is No Longer a ‘Distant Warning,’ UN Leader Says
    • How Labour can reform Britain’s pensions triple lock | State pensions
    • Trump’s plans for massive arch move ahead
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, September 25
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 25, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananSep 24, 2026Vulnerability / Web Security

    Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure.

    The vulnerability in question is CVE-2026-87902 (CVSS score: 9.2), which could allow an unauthenticated attacker to obtain remote code execution (RCE).

    “An unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable local .php file outside the active theme directories,” WordPress said in an advisory released two days ago. “If relevant preconditions for both the server environment and the active theme are met, this can lead to RCE.”

    Cybersecurity

    Successful exploitation hinges on meeting the two pre-requisites –

    • The active child or parent theme contains a top-level directory whose name starts with page- (e.g., page-templates).
    • A chosen local .php target file exists on the server and is readable by the web server account. (e.g., pearcmd.php).

    In a statement shared with The Hacker News, Previdian said it’s seeing exploitation attempts targeting CVE-2026-87902 against its honeypot network, with the malicious requests originating from an IP address (104.194.9[.]227) located in the U.S. state of New Jersey.

    These requests include the local PHP file /usr/local/lib/php/pearcmd.php, writing a file to /tmp/, and then including a PHP upload script hosted on GitHub (“raw.githubusercontent[.]com/MrG3P5/web-shell/refs/heads/main/uploader.php”).

    “Although this is undoubtedly a serious vulnerability, certain preconditions make exploitation less likely,” Previdian’s founder and CEO Ryan Dewhurst said. “Because WordPress has auto-updates enabled by default, we’re likely to see mass-exploitation attempts, but relatively few actual compromises.”

    Telemetry data from Previdian has recorded a total of 68 exploitation attempts starting September 23, 2026. Some of the efforts have also originated from an Indonesia-based IP address.

    WordPress security company Patchstack has also warned that the malicious requests have expanded from reconnaissance against harmless core files to active exploitation in which attackers include “pearcmd.php” and use it to write PHP files to disk, corroborating findings from Previdian.

    Cybersecurity

    The first exploitation effort was recorded on September 22, 2026, at 11:49 a.m. UTC, the same day patches were shipped for the flaw. In addition, the activity involves arbitrary file writes with attacker-controlled PHP content in locations like “/tmp” and “/var/tmp.” Observed file names include –

    • wp-pear-rce-flag.php
    • poc87902.php
    • luci_.php
    • zeta_.php

    Some of the IP addresses linked to the malicious attacks –

    • 43.250.53[.]42
    • 180.251.159[.]243
    • 195.178.110[.]247
    • 107.189.14[.]87
    • 45.61.184[.]170
    • 92.246.130[.]76

    In light of active exploitation, website administrators are advised to apply WordPress version 7.1.2 (or 7.0.6, 6.9.9, 6.8.10) as soon as possible and audit for signs of malicious activity.

    Attackers CVE202687902 Disclosure exploit hours WordPress
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers

    TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords

    CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks

    PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

    Elementor WordPress flaw lets attackers create admin accounts

    Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Crusoe abandons $1.25B plan to use Boom turbines at AI data centers

    September 25, 2026

    Liquid AI Releases LFM2.5-VL-3B-DSpark: Speculative Decoding for Vision-Language Models With Up to 3.13x Faster Decoding

    September 25, 2026

    F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers

    September 25, 2026

    US Prosecutors Want $84.2 Million From a Bank Tied to Tether

    September 25, 2026
    Latest Posts

    A Growing Number of Election Deniers Hold Key Local Roles in Midterms

    August 6, 2026

    Lithuania warns Russia could be considering possible ‘false flag’ strike on the Baltics – Europe live | Europe

    August 6, 2026

    Will Mamdani’s city-run grocery stores require ID to shop? Here’s the truth

    August 6, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Crusoe abandons $1.25B plan to use Boom turbines at AI data centers

    September 25, 2026

    Liquid AI Releases LFM2.5-VL-3B-DSpark: Speculative Decoding for Vision-Language Models With Up to 3.13x Faster Decoding

    September 25, 2026

    F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers

    September 25, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.