[SECURITY]■ STORY TIMELINE
WORDPRESS FLAW UNDER ACTIVE EXPLOIT FOR CODE EXECUTION
Threat actors are actively exploiting CVE-2026-87902, a critical WordPress vulnerability, to execute arbitrary code on affected sites. The attacks have progressed from reconnaissance to writing malicious files that execute shell commands.
Bleeping Computer+0m
Threat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to exploiting the flaw to write files…