Close Menu
NCIJ Network NCIJ Network
    What's Hot

    How Labour can reform Britain’s pensions triple lock | State pensions

    September 25, 2026

    Trump’s plans for massive arch move ahead

    September 25, 2026

    OpenAI investigating ‘dozens’ of instances of agents acting improperly

    September 25, 2026
    Facebook X (Twitter) Instagram
    Trending
    • How Labour can reform Britain’s pensions triple lock | State pensions
    • Trump’s plans for massive arch move ahead
    • OpenAI investigating ‘dozens’ of instances of agents acting improperly
    • Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure
    • U.S. SEC’s steadiest crypto advocate, Hester Peirce, to depart next week
    • First stellar stream beyond the Milky Way could reveal dark matter
    • Cheetah cubs at Prague Zoo are doing well after a period of strong storms and their mother’s illness
    • Australian interconnector granted final approval before construction
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, September 25
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 25, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananSep 24, 2026Vulnerability / Web Security

    Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure.

    The vulnerability in question is CVE-2026-87902 (CVSS score: 9.2), which could allow an unauthenticated attacker to obtain remote code execution (RCE).

    “An unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable local .php file outside the active theme directories,” WordPress said in an advisory released two days ago. “If relevant preconditions for both the server environment and the active theme are met, this can lead to RCE.”

    Cybersecurity

    Successful exploitation hinges on meeting the two pre-requisites –

    • The active child or parent theme contains a top-level directory whose name starts with page- (e.g., page-templates).
    • A chosen local .php target file exists on the server and is readable by the web server account. (e.g., pearcmd.php).

    In a statement shared with The Hacker News, Previdian said it’s seeing exploitation attempts targeting CVE-2026-87902 against its honeypot network, with the malicious requests originating from an IP address (104.194.9[.]227) located in the U.S. state of New Jersey.

    These requests include the local PHP file /usr/local/lib/php/pearcmd.php, writing a file to /tmp/, and then including a PHP upload script hosted on GitHub (“raw.githubusercontent[.]com/MrG3P5/web-shell/refs/heads/main/uploader.php”).

    “Although this is undoubtedly a serious vulnerability, certain preconditions make exploitation less likely,” Previdian’s founder and CEO Ryan Dewhurst said. “Because WordPress has auto-updates enabled by default, we’re likely to see mass-exploitation attempts, but relatively few actual compromises.”

    Telemetry data from Previdian has recorded a total of 68 exploitation attempts starting September 23, 2026. Some of the efforts have also originated from an Indonesia-based IP address.

    WordPress security company Patchstack has also warned that the malicious requests have expanded from reconnaissance against harmless core files to active exploitation in which attackers include “pearcmd.php” and use it to write PHP files to disk, corroborating findings from Previdian.

    Cybersecurity

    The first exploitation effort was recorded on September 22, 2026, at 11:49 a.m. UTC, the same day patches were shipped for the flaw. In addition, the activity involves arbitrary file writes with attacker-controlled PHP content in locations like “/tmp” and “/var/tmp.” Observed file names include –

    • wp-pear-rce-flag.php
    • poc87902.php
    • luci_.php
    • zeta_.php

    Some of the IP addresses linked to the malicious attacks –

    • 43.250.53[.]42
    • 180.251.159[.]243
    • 195.178.110[.]247
    • 107.189.14[.]87
    • 45.61.184[.]170
    • 92.246.130[.]76

    In light of active exploitation, website administrators are advised to apply WordPress version 7.1.2 (or 7.0.6, 6.9.9, 6.8.10) as soon as possible and audit for signs of malicious activity.

    Attackers CVE202687902 Disclosure exploit hours WordPress
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords

    CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks

    PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

    Elementor WordPress flaw lets attackers create admin accounts

    Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

    Anthropic rolls out up to $250 in free Claude Code credits, but only for cloud sessions

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    How Labour can reform Britain’s pensions triple lock | State pensions

    September 25, 2026

    Trump’s plans for massive arch move ahead

    September 25, 2026

    OpenAI investigating ‘dozens’ of instances of agents acting improperly

    September 25, 2026

    Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure

    September 25, 2026
    Latest Posts

    A Growing Number of Election Deniers Hold Key Local Roles in Midterms

    August 6, 2026

    Lithuania warns Russia could be considering possible ‘false flag’ strike on the Baltics – Europe live | Europe

    August 6, 2026

    Will Mamdani’s city-run grocery stores require ID to shop? Here’s the truth

    August 6, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    How Labour can reform Britain’s pensions triple lock | State pensions

    September 25, 2026

    Trump’s plans for massive arch move ahead

    September 25, 2026

    OpenAI investigating ‘dozens’ of instances of agents acting improperly

    September 25, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.