INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Exploiting WordPress CVE-2026-87902 Within Hours of Disclosure
| 2026-09-24 05:36 CRITICAL HIGHExecutive Summary AI-generated
The threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure. The vulnerability, CVE-2026-87902, allows an unauthenticated attacker to obtain remote code execution (RCE). Previdian has recorded 68 exploitation attempts starting September 23, 2026, and the first exploitation effort was recorded on September 22, 2026, at 11:49 a.m. Initial attack traffic was only for reconnaissance and started less than five hours after the patch was released in WordPress 7.1.2.
Technical Mitigations AI-generated
* Regularly update WordPress and plugins: Ensure that your website is running the latest version of WordPress, including any necessary security patches or updates. Also, regularly review and update all plugins to ensure they are not vulnerable to known exploits.
* Use a web application firewall (WAF): Consider installing a WAF like Cloudflare or ModSecurity to help block malicious traffic and reduce the risk of exploitation attempts.
* Implement content delivery networks (CDNs) for sensitive files: If your website stores sensitive data, consider using a CDN to deliver those files from a secure location. This can help prevent attackers from accessing them directly.
* Use a web application firewall (WAF): Consider installing a WAF like Cloudflare or ModSecurity to help block malicious traffic and reduce the risk of exploitation attempts.
Note: These are general recommendations, and specific mitigations may vary depending on your website's unique circumstances.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-87902CVE-2026-87902
Target & Sectors
Global Scope
Incident Timeline
September 17
Threat actors exploited a previously unknown critical WordPress flaw, allowing them to execute code on targeted sites via spear-phishing.
Click on any entity below to view its context and source!
infrastructure
7.1.1
That includes 7.1.1, from WordPress's
September 17 security release
, so a site updated less than a week ago still needs this one.
September 22, 2026
Threat actors used spear-phishing to exploit a critical WordPress flaw.
Sep 22, 2026
Threat actors exploited a previously unknown critical WordPress flaw to gain unauthorized access and execute malicious code via spear-phishing attacks.
2026/09/22
Threat actors used a previously unknown vulnerability in WordPress to target users of version 7.1.2, exploiting CVE-2026-87902.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-87902
WordPress addressed CVE-2026-87902 yesterday with the release of
version 7.1.2
, and fixes have also been backported to all branches down to 4.7 because of the critical severity of the flaw.
infrastructure
7.1.2
WordPress addressed CVE-2026-87902 yesterday with the release of
version 7.1.2
, and fixes have also been backported to all branches down to 4.7 because of the critical severity of the flaw.
infrastructure
4.7
WordPress addressed CVE-2026-87902 yesterday with the release of
version 7.1.2
, and fixes have also been backported to all branches down to 4.7 because of the critical severity of the flaw.
organisation
CVE-2026
WordPress addressed CVE-2026-87902 yesterday with the release of
version 7.1.2
, and fixes have also been backported to all branches down to 4.7 because of the critical severity of the flaw.
September 22
Threat actors used a previously unknown critical WordPress flaw to target multiple sites under the protection of Patchstack.
Click on any entity below to view its context and source!
organisation
IP
WordPress security firm Patchstack reports that it observed the first malicious requests at 17:44 UTC on September 22 from a small group of IP addresses targeting multiple sites under its protection.
organisation
Patchstack
WordPress security firm Patchstack reports that it observed the first malicious requests at 17:44 UTC on September 22 from a small group of IP addresses targeting multiple sites under its protection.
organisation
UTC
WordPress security firm Patchstack reports that it observed the first malicious requests at 17:44 UTC on September 22 from a small group of IP addresses targeting multiple sites under its protection.
infrastructure
7.1.2
The fix shipped on September 22 in WordPress 7.1.2, with fixes for every branch the project still supports, back to 4.7, and WordPress is telling site owners to
update now
.
infrastructure
4.7
The fix shipped on September 22 in WordPress 7.1.2, with fixes for every branch the project still supports, back to 4.7, and WordPress is telling site owners to
update now
.
tactic
T1588.006 - Vulnerabilities
As of September 22, there were no reports of the flaw being used in attacks, and it had no entry in the U.S. CISA Known Exploited Vulnerabilities catalog.
September 23, 2026
Threat actors used spear-phishing to target a WordPress website.
Click on any entity below to view its context and source!
general_metric
68 exploitation attempts
"
Telemetry data from Previdian has
recorded
a total of 68 exploitation attempts starting September 23, 2026.
2026/09/23
Researchers discovered a critical WordPress flaw allowing threat actors to exploit it for code execution via spear-phishing.
Sep 24, 2026
Threat actors used a known critical WordPress flaw to gain unauthorized access and execute malicious code via spear-phishing attacks on the targeted organization.
2026/09/24
Threat actors exploited a critical WordPress flaw allowing remote code execution via spear-phishing attacks within hours of disclosure.
Click on any entity below to view its context and source!
organisation
The Hacker News
In a statement shared with The Hacker News, Previdian said it's seeing exploitation attempts targeting CVE-2026-87902 against its honeypot network, with the malicious requests originating from an IP address (104.194.9[.]227) located in the U.S. state of New Jersey.
organisation
Previdian
In a statement shared with The Hacker News, Previdian said it's seeing exploitation attempts targeting CVE-2026-87902 against its honeypot network, with the malicious requests originating from an IP address (104.194.9[.]227) located in the U.S. state of New Jersey.
organisation
IP
In a statement shared with The Hacker News, Previdian said it's seeing exploitation attempts targeting CVE-2026-87902 against its honeypot network, with the malicious requests originating from an IP address (104.194.9[.]227) located in the U.S. state of New Jersey.
organisation
Exploit WordPress CVE-2026-87902
Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure.
organisation
CVE-2026-87902
Threat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to exploiting the flaw to write files to disk that execute shell commands when accessed.
infrastructure
7.1.2
Given the active exploitation of CVE-2026-87902, website administrators should update to WordPress version 7.1.2 as soon as possible and review the logs for malicious activity.
Initial attack traffic was only for reconnaissance and started less than five hours after the patch was released in WordPress 7.1.2.
In light of active exploitation, website administrators are advised to apply WordPress version 7.1.2 (or 7.0.6, 6.9.9, 6.8.10) as soon as possible and audit for signs of malicious activity.
The release to update to depends on the branch you run:
Branch you run
Update to
7.1.x
7.1.2
7.0.x
7.0.6
6.9.x
6.9.9
6.8.x
6.8.10
6.7.x
6.7.9
6.6.x
6.6.9
WordPress backported the fix to every older branch it still supports as a courtesy, down to 4.7.37.
organisation
CVSS
WordPress rates the flaw as critical, assigns it a CVSS score of 9.2, and assigns it
CVE-2026-87902
.
organisation
Patchstack
WordPress security company Patchstack has also
warned
that the malicious requests have expanded from reconnaissance against harmless core files to active exploitation in which attackers include "pearcmd.php" and use it to write PHP files to disk, corroborating findings from Previdian.
organisation
PHP
These requests include the local PHP file /usr/local/lib/php/pearcmd.php, writing a file to /tmp/, and then including a PHP upload script hosted on GitHub ("raw.githubusercontent[.]com/MrG3P5/web-shell/refs/heads/main/uploader.php").
The WordPress advisory notes that the official PHP image for Docker is affected, and so is the default cPanel configuration when a PHP version before 8.5 is used.
Swati Khandelwal
Sep 22, 2026
Vulnerability / Web Security
WordPress has fixed a critical flaw in its core software that lets an attacker with no account make a site load a PHP file from outside its theme folders.
organisation
GitHub
These requests include the local PHP file /usr/local/lib/php/pearcmd.php, writing a file to /tmp/, and then including a PHP upload script hosted on GitHub ("raw.githubusercontent[.]com/MrG3P5/web-shell/refs/heads/main/uploader.php").
organisation
PHP’s
The advisory gives pearcmd.php as an example when PHP’s register_argc_argv setting is active.
infrastructure
8.5
The WordPress advisory notes that the official PHP image for Docker is affected, and so is the default cPanel configuration when a PHP version before 8.5 is used.
That setting is off by default on PHP 8.5 and on by default on older PHP versions.
organisation
cPanel
The WordPress advisory notes that the official PHP image for Docker is affected, and so is the default cPanel configuration when a PHP version before 8.5 is used.
organisation
Vulnerability / Web Security
Swati Khandelwal
Sep 22, 2026
Vulnerability / Web Security
WordPress has fixed a critical flaw in its core software that lets an attacker with no account make a site load a PHP file from outside its theme folders.
Ravie Lakshmanan
Sep 24, 2026
Vulnerability / Web Security
Threat actors have begun to actively exploit a
critical security flaw
in WordPress within hours of public disclosure.
infrastructure
7.0.6
In light of active exploitation, website administrators are advised to apply WordPress version 7.1.2 (or 7.0.6, 6.9.9, 6.8.10) as soon as possible and audit for signs of malicious activity.
The release to update to depends on the branch you run:
Branch you run
Update to
7.1.x
7.1.2
7.0.x
7.0.6
6.9.x
6.9.9
6.8.x
6.8.10
6.7.x
6.7.9
6.6.x
6.6.9
WordPress backported the fix to every older branch it still supports as a courtesy, down to 4.7.37.
infrastructure
6.9.9
In light of active exploitation, website administrators are advised to apply WordPress version 7.1.2 (or 7.0.6, 6.9.9, 6.8.10) as soon as possible and audit for signs of malicious activity.
The release to update to depends on the branch you run:
Branch you run
Update to
7.1.x
7.1.2
7.0.x
7.0.6
6.9.x
6.9.9
6.8.x
6.8.10
6.7.x
6.7.9
6.6.x
6.6.9
WordPress backported the fix to every older branch it still supports as a courtesy, down to 4.7.37.
infrastructure
6.8.10
In light of active exploitation, website administrators are advised to apply WordPress version 7.1.2 (or 7.0.6, 6.9.9, 6.8.10) as soon as possible and audit for signs of malicious activity.
The release to update to depends on the branch you run:
Branch you run
Update to
7.1.x
7.1.2
7.0.x
7.0.6
6.9.x
6.9.9
6.8.x
6.8.10
6.7.x
6.7.9
6.6.x
6.6.9
WordPress backported the fix to every older branch it still supports as a courtesy, down to 4.7.37.
infrastructure
7.1
The release to update to depends on the branch you run:
Branch you run
Update to
7.1.x
7.1.2
7.0.x
7.0.6
6.9.x
6.9.9
6.8.x
6.8.10
6.7.x
6.7.9
6.6.x
6.6.9
WordPress backported the fix to every older branch it still supports as a courtesy, down to 4.7.37.
infrastructure
7.0
The release to update to depends on the branch you run:
Branch you run
Update to
7.1.x
7.1.2
7.0.x
7.0.6
6.9.x
6.9.9
6.8.x
6.8.10
6.7.x
6.7.9
6.6.x
6.6.9
WordPress backported the fix to every older branch it still supports as a courtesy, down to 4.7.37.
infrastructure
6.9
The release to update to depends on the branch you run:
Branch you run
Update to
7.1.x
7.1.2
7.0.x
7.0.6
6.9.x
6.9.9
6.8.x
6.8.10
6.7.x
6.7.9
6.6.x
6.6.9
WordPress backported the fix to every older branch it still supports as a courtesy, down to 4.7.37.
infrastructure
6.8
The release to update to depends on the branch you run:
Branch you run
Update to
7.1.x
7.1.2
7.0.x
7.0.6
6.9.x
6.9.9
6.8.x
6.8.10
6.7.x
6.7.9
6.6.x
6.6.9
WordPress backported the fix to every older branch it still supports as a courtesy, down to 4.7.37.
infrastructure
6.7
The release to update to depends on the branch you run:
Branch you run
Update to
7.1.x
7.1.2
7.0.x
7.0.6
6.9.x
6.9.9
6.8.x
6.8.10
6.7.x
6.7.9
6.6.x
6.6.9
WordPress backported the fix to every older branch it still supports as a courtesy, down to 4.7.37.
infrastructure
6.7.9
The release to update to depends on the branch you run:
Branch you run
Update to
7.1.x
7.1.2
7.0.x
7.0.6
6.9.x
6.9.9
6.8.x
6.8.10
6.7.x
6.7.9
6.6.x
6.6.9
WordPress backported the fix to every older branch it still supports as a courtesy, down to 4.7.37.
infrastructure
6.6
The release to update to depends on the branch you run:
Branch you run
Update to
7.1.x
7.1.2
7.0.x
7.0.6
6.9.x
6.9.9
6.8.x
6.8.10
6.7.x
6.7.9
6.6.x
6.6.9
WordPress backported the fix to every older branch it still supports as a courtesy, down to 4.7.37.
infrastructure
6.6.9
The release to update to depends on the branch you run:
Branch you run
Update to
7.1.x
7.1.2
7.0.x
7.0.6
6.9.x
6.9.9
6.8.x
6.8.10
6.7.x
6.7.9
6.6.x
6.6.9
WordPress backported the fix to every older branch it still supports as a courtesy, down to 4.7.37.
infrastructure
4.7.37
The release to update to depends on the branch you run:
Branch you run
Update to
7.1.x
7.1.2
7.0.x
7.0.6
6.9.x
6.9.9
6.8.x
6.8.10
6.7.x
6.7.9
6.6.x
6.6.9
WordPress backported the fix to every older branch it still supports as a courtesy, down to 4.7.37.
organisation
WordPress
Ravie Lakshmanan
Sep 24, 2026
Vulnerability / Web Security
Threat actors have begun to actively exploit a
critical security flaw
in WordPress within hours of public disclosure.
Hackers start exploiting critical WordPress flaw for code execution.
WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers.
organisation
RCE
"If relevant preconditions for both the server environment and the active theme are met, this can lead to RCE.
organisation
PHP 8.5
That setting is off by default on PHP 8.5 and on by default on older PHP versions.
infrastructure
4.6
Releases before 4.6 will not be getting a fix for this flaw.
organisation
NFL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
organisation
CHANEL
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
infrastructure
4.7.0
Every version from 4.7.0 through 7.1.1 is affected.
infrastructure
7.1.1
Every version from 4.7.0 through 7.1.1 is affected.
infrastructure
7.0.2
His demonstrated attack ran code with the privileges of the web-server account, not full control of the server, and he tested it against WordPress 7.0.2 in isolated local labs, not the patched release or any live site.
organisation
Updates
Others can update from the dashboard under Updates, or download the release from WordPress.org.
organisation
WordPress.org
Others can update from the dashboard under Updates, or download the release from WordPress.org.
organisation
HackerOne
WordPress credited
Robert Ressl
with finding the flaw, which he disclosed privately through its HackerOne program in July.
Tactical Metrics
Metrics
infrastructure
7.1.2
Software Version
Click for context!
In light of active exploitation, website administrators are advised to apply WordPress version 7.1.2 (or 7.0.6, 6.9.9, 6.8.10) as soon as possible and audit for signs of malicious activity.
Initial attack traffic was only for reconnaissance and started less than five hours after the patch was released in WordPress 7.1.2.
WordPress addressed CVE-2026-87902 yesterday with the release of
version 7.1.2
, and fixes have also been backported to all branches down to 4.7 because of the critical severity of the flaw.
Given the active exploitation of CVE-2026-87902, website administrators should update to WordPress version 7.1.2 as soon as possible and review the logs for malicious activity.
The fix shipped on September 22 in WordPress 7.1.2, with fixes for every branch the project still supports, back to 4.7, and WordPress is telling site owners to
update now
.
The release to update to depends on the branch you run:
Branch you run
Update to
7.1.x
7.1.2
7.0.x
7.0.6
6.9.x
6.9.9
6.8.x
6.8.10
6.7.x
6.7.9
6.6.x
6.6.9
WordPress backported the fix to every older branch it still supports as a courtesy, down to 4.7.37.
Metrics
infrastructure
7.0.6
Software Version
In light of active exploitation, website administrators are advised to apply WordPress version 7.1.2 (or 7.0.6, 6.9.9, 6.8.10) as soon as possible and audit for signs of malicious activity.
The release to update to depends on the branch you run:
Branch you run
Update to
7.1.x
7.1.2
7.0.x
7.0.6
6.9.x
6.9.9
6.8.x
6.8.10
6.7.x
6.7.9
6.6.x
6.6.9
WordPress backported the fix to every older branch it still supports as a courtesy, down to 4.7.37.
Metrics
infrastructure
6.9.9
Software Version
In light of active exploitation, website administrators are advised to apply WordPress version 7.1.2 (or 7.0.6, 6.9.9, 6.8.10) as soon as possible and audit for signs of malicious activity.
The release to update to depends on the branch you run:
Branch you run
Update to
7.1.x
7.1.2
7.0.x
7.0.6
6.9.x
6.9.9
6.8.x
6.8.10
6.7.x
6.7.9
6.6.x
6.6.9
WordPress backported the fix to every older branch it still supports as a courtesy, down to 4.7.37.
Metrics
infrastructure
6.8.10
Software Version
In light of active exploitation, website administrators are advised to apply WordPress version 7.1.2 (or 7.0.6, 6.9.9, 6.8.10) as soon as possible and audit for signs of malicious activity.
The release to update to depends on the branch you run:
Branch you run
Update to
7.1.x
7.1.2
7.0.x
7.0.6
6.9.x
6.9.9
6.8.x
6.8.10
6.7.x
6.7.9
6.6.x
6.6.9
WordPress backported the fix to every older branch it still supports as a courtesy, down to 4.7.37.
Metrics
infrastructure
8.5
Software Version
The WordPress advisory notes that the official PHP image for Docker is affected, and so is the default cPanel configuration when a PHP version before 8.5 is used.
That setting is off by default on PHP 8.5 and on by default on older PHP versions.
Metrics
infrastructure
4.7
Software Version
WordPress addressed CVE-2026-87902 yesterday with the release of
version 7.1.2
, and fixes have also been backported to all branches down to 4.7 because of the critical severity of the flaw.
The fix shipped on September 22 in WordPress 7.1.2, with fixes for every branch the project still supports, back to 4.7, and WordPress is telling site owners to
update now
.
Metrics
infrastructure
4.6
Software Version
Releases before 4.6 will not be getting a fix for this flaw.
Metrics
infrastructure
4.7.0
Software Version
Every version from 4.7.0 through 7.1.1 is affected.
Metrics
infrastructure
7.1.1
Software Version
Every version from 4.7.0 through 7.1.1 is affected.
That includes 7.1.1, from WordPress's
September 17 security release
, so a site updated less than a week ago still needs this one.
Metrics
infrastructure
7.1
Software Version
The release to update to depends on the branch you run:
Branch you run
Update to
7.1.x
7.1.2
7.0.x
7.0.6
6.9.x
6.9.9
6.8.x
6.8.10
6.7.x
6.7.9
6.6.x
6.6.9
WordPress backported the fix to every older branch it still supports as a courtesy, down to 4.7.37.
Metrics
infrastructure
7.0
Software Version
The release to update to depends on the branch you run:
Branch you run
Update to
7.1.x
7.1.2
7.0.x
7.0.6
6.9.x
6.9.9
6.8.x
6.8.10
6.7.x
6.7.9
6.6.x
6.6.9
WordPress backported the fix to every older branch it still supports as a courtesy, down to 4.7.37.
Metrics
infrastructure
6.9
Software Version
The release to update to depends on the branch you run:
Branch you run
Update to
7.1.x
7.1.2
7.0.x
7.0.6
6.9.x
6.9.9
6.8.x
6.8.10
6.7.x
6.7.9
6.6.x
6.6.9
WordPress backported the fix to every older branch it still supports as a courtesy, down to 4.7.37.
Metrics
infrastructure
6.8
Software Version
The release to update to depends on the branch you run:
Branch you run
Update to
7.1.x
7.1.2
7.0.x
7.0.6
6.9.x
6.9.9
6.8.x
6.8.10
6.7.x
6.7.9
6.6.x
6.6.9
WordPress backported the fix to every older branch it still supports as a courtesy, down to 4.7.37.
Metrics
infrastructure
6.7
Software Version
The release to update to depends on the branch you run:
Branch you run
Update to
7.1.x
7.1.2
7.0.x
7.0.6
6.9.x
6.9.9
6.8.x
6.8.10
6.7.x
6.7.9
6.6.x
6.6.9
WordPress backported the fix to every older branch it still supports as a courtesy, down to 4.7.37.
Metrics
infrastructure
6.7.9
Software Version
The release to update to depends on the branch you run:
Branch you run
Update to
7.1.x
7.1.2
7.0.x
7.0.6
6.9.x
6.9.9
6.8.x
6.8.10
6.7.x
6.7.9
6.6.x
6.6.9
WordPress backported the fix to every older branch it still supports as a courtesy, down to 4.7.37.
Metrics
infrastructure
6.6
Software Version
The release to update to depends on the branch you run:
Branch you run
Update to
7.1.x
7.1.2
7.0.x
7.0.6
6.9.x
6.9.9
6.8.x
6.8.10
6.7.x
6.7.9
6.6.x
6.6.9
WordPress backported the fix to every older branch it still supports as a courtesy, down to 4.7.37.
Metrics
infrastructure
6.6.9
Software Version
The release to update to depends on the branch you run:
Branch you run
Update to
7.1.x
7.1.2
7.0.x
7.0.6
6.9.x
6.9.9
6.8.x
6.8.10
6.7.x
6.7.9
6.6.x
6.6.9
WordPress backported the fix to every older branch it still supports as a courtesy, down to 4.7.37.
Metrics
infrastructure
4.7.37
Software Version
The release to update to depends on the branch you run:
Branch you run
Update to
7.1.x
7.1.2
7.0.x
7.0.6
6.9.x
6.9.9
6.8.x
6.8.10
6.7.x
6.7.9
6.6.x
6.6.9
WordPress backported the fix to every older branch it still supports as a courtesy, down to 4.7.37.
Metrics
infrastructure
7.0.2
Software Version
His demonstrated attack ran code with the privileges of the web-server account, not full control of the server, and he tested it against WordPress 7.0.2 in isolated local labs, not the patched release or any live site.
Intelligence Sources
The Hacker News
2026-09-22
The Hacker News
2026-09-24
BleepingComputer
2026-09-23
Hackers start exploiting critical WordPress flaw for code execution
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-09-24T10:30
Comprehensive Tactical Telemetry
Highly Correlated Entities
22x
organisation
Identified Entity
The Hacker News
entity
19x
infrastructure
Software Version
7.1.2
version
11x
timeline
Temporal Reference
Sep 24, 2026
date
2x
source region
Origin Country
Jersey
country
2x
tactic
Cyber Operation Type
Reconnaissance
tactic
2x
general metric
Sep
24
sep
Contextual Telemetry
Context Block
6 METRICS
vulnerability
Exploited CVE
CVE-2026-87902
cve
general metric
Score
9
score
general metric
Exploitation Attempts
68
exploitation attempts
vulnerability
CVSS Score
9
score
general metric
Php
8
php
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.