Technology newsroom
Urgent! WordPress Critical Vulnerability (CVE-2026-87902) Discovered, Exploitation Underway – System Admins Must Update Immediately
Urgent security alert! A critical vulnerability, CVE-2026-87902, has been discovered in WordPress with a severity score of Critical (CVSS 9.2). This flaw allows unauthenticated attackers to achieve Remote Code Execution (RCE) and take control of websites. Exploitation has been observed just hours after public disclosure.
📌 Key Highlights:
* A critical security vulnerability, CVE-2026-87902, has been discovered in WordPress, with a severity score of Critical (9.2).
* Attackers have already begun exploiting this vulnerability to compromise websites within just hours of its public disclosure.
* This flaw allows unauthenticated attackers to achieve Remote Code Execution (RCE) and gain full control over websites.
An urgent alert for all WordPress website administrators: A critical security vulnerability (CVE-2026-87902) has been identified, receiving a high severity score of 9.2 (CVSS Score). Most concerning is the widespread reporting that malicious actors have already begun exploiting this flaw, mere hours after its technical details were made public.
⚙️ Technical Details of the Vulnerability
The vulnerability stems from a flaw in the get_page_template() function, allowing unauthenticated attackers to trick the system into including or calling any existing .php file on the server. This action leads to Remote Code Execution (RCE), meaning attackers can fully command and control your website.
🛡️ Immediate Action Required for System Administrators
The rapid exploitation by attackers indicates an extremely high risk. All WordPress website administrators are strongly advised to check for and apply the latest security patches from the developer as quickly as possible to close this attack vector before damage occurs. Failure to do so could result in your website being compromised, data leakage, or being used as a platform for further attacks.
💬 Is your website running WordPress? Have you checked and updated it yet?