INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Exploiting WordPress CVE-2026-87902 Within Hours of Disclosure

| 2026-09-24 05:36 CRITICAL HIGH
Executive Summary AI-generated
The threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure. The vulnerability, CVE-2026-87902, allows an unauthenticated attacker to obtain remote code execution (RCE). Previdian has recorded 68 exploitation attempts starting September 23, 2026, and the first exploitation effort was recorded on September 22, 2026, at 11:49 a.m. Initial attack traffic was only for reconnaissance and started less than five hours after the patch was released in WordPress 7.1.2.
Technical Mitigations AI-generated
* Regularly update WordPress and plugins: Ensure that your website is running the latest version of WordPress, including any necessary security patches or updates. Also, regularly review and update all plugins to ensure they are not vulnerable to known exploits. * Use a web application firewall (WAF): Consider installing a WAF like Cloudflare or ModSecurity to help block malicious traffic and reduce the risk of exploitation attempts. * Implement content delivery networks (CDNs) for sensitive files: If your website stores sensitive data, consider using a CDN to deliver those files from a secure location. This can help prevent attackers from accessing them directly. * Use a web application firewall (WAF): Consider installing a WAF like Cloudflare or ModSecurity to help block malicious traffic and reduce the risk of exploitation attempts. Note: These are general recommendations, and specific mitigations may vary depending on your website's unique circumstances.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-87902CVE-2026-87902
Target & Sectors
Global Scope
Incident Timeline
‎September 17
Threat actors exploited a previously unknown critical WordPress flaw, allowing them to execute code on targeted sites via spear-phishing.
infrastructure 7.1.1
‎September 22, 2026
Threat actors used spear-phishing to exploit a critical WordPress flaw.
‎Sep 22, 2026
Threat actors exploited a previously unknown critical WordPress flaw to gain unauthorized access and execute malicious code via spear-phishing attacks.
‎2026/09/22
Threat actors used a previously unknown vulnerability in WordPress to target users of version 7.1.2, exploiting CVE-2026-87902.
vulnerability CVE-2026-87902
infrastructure 7.1.2
infrastructure 4.7
organisation CVE-2026
‎September 22
Threat actors used a previously unknown critical WordPress flaw to target multiple sites under the protection of Patchstack.
organisation IP
organisation Patchstack
organisation UTC
infrastructure 7.1.2
infrastructure 4.7
tactic T1588.006 - Vulnerabilities
‎September 23, 2026
Threat actors used spear-phishing to target a WordPress website.
general_metric 68 exploitation attempts
‎2026/09/23
Researchers discovered a critical WordPress flaw allowing threat actors to exploit it for code execution via spear-phishing.
‎Sep 24, 2026
Threat actors used a known critical WordPress flaw to gain unauthorized access and execute malicious code via spear-phishing attacks on the targeted organization.
‎2026/09/24
Threat actors exploited a critical WordPress flaw allowing remote code execution via spear-phishing attacks within hours of disclosure.
organisation The Hacker News
organisation Previdian
organisation IP
organisation Exploit WordPress CVE-2026-87902
organisation CVE-2026-87902
infrastructure 7.1.2
organisation CVSS
organisation Patchstack
organisation PHP
organisation GitHub
organisation PHP’s
infrastructure 8.5
organisation cPanel
organisation Vulnerability / Web Security
infrastructure 7.0.6
infrastructure 6.9.9
infrastructure 6.8.10
infrastructure 7.1
infrastructure 7.0
infrastructure 6.9
infrastructure 6.8
infrastructure 6.7
infrastructure 6.7.9
infrastructure 6.6
infrastructure 6.6.9
infrastructure 4.7.37
organisation WordPress
organisation RCE
organisation PHP 8.5
infrastructure 4.6
organisation NFL
organisation CHANEL
infrastructure 4.7.0
infrastructure 7.1.1
infrastructure 7.0.2
organisation Updates
organisation WordPress.org
organisation HackerOne
Tactical Metrics
Metrics
infrastructure
‎7.1.2
Software Version
Metrics
infrastructure
‎7.0.6
Software Version
Metrics
infrastructure
‎6.9.9
Software Version
Metrics
infrastructure
‎6.8.10
Software Version
Metrics
infrastructure
‎8.5
Software Version
Metrics
infrastructure
‎4.7
Software Version
Metrics
infrastructure
‎4.6
Software Version
Metrics
infrastructure
‎4.7.0
Software Version
Metrics
infrastructure
‎7.1.1
Software Version
Metrics
infrastructure
‎7.1
Software Version
Metrics
infrastructure
‎7.0
Software Version
Metrics
infrastructure
‎6.9
Software Version
Metrics
infrastructure
‎6.8
Software Version
Metrics
infrastructure
‎6.7
Software Version
Metrics
infrastructure
‎6.7.9
Software Version
Metrics
infrastructure
‎6.6
Software Version
Metrics
infrastructure
‎6.6.9
Software Version
Metrics
infrastructure
‎4.7.37
Software Version
Metrics
infrastructure
‎7.0.2
Software Version