hacker-news · Crawled Sep 24, 2026

Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure

13 IoCs
Read original article ↗

AI Summary

Threat actors are actively exploiting CVE-2026-87902, a critical vulnerability in WordPress that allows unauthenticated remote code execution (RCE) under specific conditions. Exploitation requires the active theme to have a directory starting with 'page-' and a readable local PHP file such as 'pearcmd.php' on the server. Attackers are leveraging the vulnerability to write PHP web shells to temporary directories and are retrieving payloads from a GitHub repository. Multiple IP addresses have been observed conducting exploitation attempts, with the first recorded just hours after the patch was released.

AI-extracted · verify before operational use

Indicators of Compromise 13 extracted

Type Value Detail
IP 104[.]194[.]9[.]227 Details →
IP 43[.]250[.]53[.]42 Details →
IP 180[.]251[.]159[.]243 Details →
IP 195[.]178[.]110[.]247 Details →
IP 107[.]189[.]14[.]87 Details →
IP 45[.]61[.]184[.]170 Details →
IP 92[.]246[.]130[.]76 Details →
GitHub Repo MrG3P5/web-shell Details →
Filename pearcmd.php Details →
Filename wp-pear-rce-flag.php Details →
Filename poc87902.php Details →
Filename luci_<random>.php Details →
Filename zeta_<random>.php Details →