> Hackers start exploiting critical WordPress flaw for code execution
[AUTHOR: Bill Toulas]
[DATE: 23/09/2026 18:31]
[LANGUAGE: EN]
Threat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to exploiting the flaw to write files to disk that execute shell commands when accessed. [...]