SPOJENO AI EPSS 0.00 (nejvyšší)
Hackers start exploiting critical WordPress flaw for code execution
Threat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to exploiting the flaw to write files to disk that execute shell commands when accessed. [...]
WordPress FI US CA NL IT FR
CVE v události 2
| CVE | hodnocení | KEV | EPSS |
|---|---|---|---|
| CVE-2026-87902 | 8.1 3.1 · CISA-ADP | – | 0.00 |
| CVE-2026-93485 | 7.1 3.1 · Patchstack | – | 0.00 |
Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 9.2.
Jak se o tom psalo 9
-
· NCSC-FI FI
WordPress Core – Critical Path Traversal Vulnerability
Classification: Critical, Solution: Official Fix, Exploit Maturity: Proof-of-Concept, CVSSv4.0: 9.2, CVEs: CVE-2026-87902, Summary: A critical path-traversal vulnerability has been corrected in WordPress Core. An unauthenticated attacker can manipulate page-template resolution so that WordPress includes a chosen readable local PHP file outside the active theme directories. Under compatible theme and server conditions, exploitation can result in remote code execution and complete website…
-
· BleepingComputer US nadpis události
Hackers start exploiting critical WordPress flaw for code execution
Threat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to exploiting the flaw to write files to disk that execute shell commands when accessed. [...]
-
· Cyber Centre Kanada CA
WordPress security advisory (AV26-952)
Serial number: AV26-952Date: September 23, 2026 As of September 22, 2026, WordPress is affected by a vulnerability in the following product: WordPress Prior to 7.1.2 Open-source reporting indicates that CVE-2026-87902 is being exploited in the wild. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Unauthenticated path traversal in page-template resolution leading to conditional RCE · Advisory ·…
-
· NCSC-NL NL
NCSC-2026-0389 [1.00] [M/H] Kwetsbaarheid verholpen in WordPress
De ontwikkelaars van WordPress hebben een kwetsbaarheid verholpen in WordPress. Een kwaadwillende kan de kwetsbaarheid met kenmerk CVE-2026-87902 misbruiken, om zonder authenticatie een lokaal PHP-bestand buiten de actieve themamappen door WordPress te laten inladen. Onder bepaalde voorwaarden met betrekking tot het actieve thema en de serverconfiguratie kan de kwetsbaarheid leiden tot het uitvoeren van willekeurige code op de server. Hierdoor kan een kwaadwillende mogelijk toegang krijgen tot…
-
· CSIRT Itálie (ACN) IT
WordPress: PoC pubbliche per lo sfruttamento di nuove vulnerabilità
Disponibili Proof of Concept (PoC) per lo sfruttamento di tre vulnerabilità, già sanate dal vendor, che interessano il prodotto WordPress Core.
-
· NCSC-FI FI
WordPress Core - Multiple Severe Vulnerabilities
Classification: Severe, Solution: Official Fix, Exploit Maturity: Functional, CVSSv3.1: None, CVEs: , Summary: WordPress 7.1.1 addresses 11 security vulnerabilities in WordPress Core. The fixes include stored cross-site scripting, authenticated path traversal, authorization vulnerabilities and an issue where a specially crafted URL can cause an authenticated administrator's browser to automatically install and preview an inactive theme from WordPress.org. Public security research has…
-
· CERT-FR – avis FR
Vulnérabilité dans WordPress (23 septembre 2026)
Une vulnérabilité a été découverte dans WordPress. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance.
-
· BleepingComputer US
WordPress Click2Shell flaw lets hackers execute PHP on the server
Technical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed 'Click2Shell' that affects the platform's Core component. [...]
-
· CERT-FR – avis FR
Multiples vulnérabilités dans WordPress (18 septembre 2026)
De multiples vulnérabilités ont été découvertes dans WordPress. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, une injection de code indirecte à distance (XSS) et un contournement de la politique de sécurité.