← nejvýznamnější zprávy · všechny zprávy

SPOJENO AI EPSS 0.00 (nejvyšší)

Hackers start exploiting critical WordPress flaw for code execution

Threat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to exploiting the flaw to write files to disk that execute shell commands when accessed. [...]

Číst originál na BleepingComputer →

9 zpráv z 6 zdrojů · první 18. 9. 02:00 · poslední 24. 9. 04:00 CZ · EN/orig

WordPress FI US CA NL IT FR

tg: zneužíváno tg: zranitelnost tg: rozbor tg: novinka v produktu

CVE v události 2

CVEhodnoceníKEVEPSS
CVE-2026-87902 8.1 3.1 · CISA-ADP 0.00
CVE-2026-93485 7.1 3.1 · Patchstack 0.00

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 9.2.

Jak se o tom psalo 9

  1. · NCSC-FI FI

    WordPress Core – Critical Path Traversal Vulnerability

    Classification: Critical, Solution: Official Fix, Exploit Maturity: Proof-of-Concept, CVSSv4.0: 9.2, CVEs: CVE-2026-87902, Summary: A critical path-traversal vulnerability has been corrected in WordPress Core. An unauthenticated attacker can manipulate page-template resolution so that WordPress includes a chosen readable local PHP file outside the active theme directories. Under compatible theme and server conditions, exploitation can result in remote code execution and complete website…

  2. · BleepingComputer US nadpis události

    Hackers start exploiting critical WordPress flaw for code execution

    Threat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to exploiting the flaw to write files to disk that execute shell commands when accessed. [...]

  3. · Cyber Centre Kanada CA

    WordPress security advisory (AV26-952)

    Serial number: AV26-952Date: September 23, 2026 As of September 22, 2026, WordPress is affected by a vulnerability in the following product: WordPress Prior to 7.1.2 Open-source reporting indicates that CVE-2026-87902 is being exploited in the wild. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Unauthenticated path traversal in page-template resolution leading to conditional RCE · Advisory ·…

  4. · NCSC-NL NL

    NCSC-2026-0389 [1.00] [M/H] Kwetsbaarheid verholpen in WordPress

    De ontwikkelaars van WordPress hebben een kwetsbaarheid verholpen in WordPress. Een kwaadwillende kan de kwetsbaarheid met kenmerk CVE-2026-87902 misbruiken, om zonder authenticatie een lokaal PHP-bestand buiten de actieve themamappen door WordPress te laten inladen. Onder bepaalde voorwaarden met betrekking tot het actieve thema en de serverconfiguratie kan de kwetsbaarheid leiden tot het uitvoeren van willekeurige code op de server. Hierdoor kan een kwaadwillende mogelijk toegang krijgen tot…

  5. · CSIRT Itálie (ACN) IT

    WordPress: PoC pubbliche per lo sfruttamento di nuove vulnerabilità

    Disponibili Proof of Concept (PoC) per lo sfruttamento di tre vulnerabilità, già sanate dal vendor, che interessano il prodotto WordPress Core.

  6. · NCSC-FI FI

    WordPress Core - Multiple Severe Vulnerabilities

    Classification: Severe, Solution: Official Fix, Exploit Maturity: Functional, CVSSv3.1: None, CVEs: , Summary: WordPress 7.1.1 addresses 11 security vulnerabilities in WordPress Core. The fixes include stored cross-site scripting, authenticated path traversal, authorization vulnerabilities and an issue where a specially crafted URL can cause an authenticated administrator's browser to automatically install and preview an inactive theme from WordPress.org. Public security research has…

  7. · CERT-FR – avis FR

    Vulnérabilité dans WordPress (23 septembre 2026)

    Une vulnérabilité a été découverte dans WordPress. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance.

  8. · BleepingComputer US

    WordPress Click2Shell flaw lets hackers execute PHP on the server

    Technical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed 'Click2Shell' that affects the platform's Core component. [...]

  9. · CERT-FR – avis FR

    Multiples vulnérabilités dans WordPress (18 septembre 2026)

    De multiples vulnérabilités ont été découvertes dans WordPress. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, une injection de code indirecte à distance (XSS) et un contournement de la politique de sécurité.