💻
Critical WordPress vulnerability actively exploited: urgent update needed
💻 Technology

Critical WordPress vulnerability actively exploited: urgent update needed

Hackers are actively exploiting CVE-2026-87902, a path traversal vulnerability in WordPress core with a severity rating of 8.1/10 that allows PHP file inclusion and potential full site takeover. A patch was released in version 7.1.2 and backported to 4.7 and later; exploitation began within hours of disclosure. Site administrators should immediately update installations or temporarily block path traversal sequences and disable risky PHP settings.

Comments

No comments yet