hacker-news · Crawled Sep 24, 2026
Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure
13 IoCs
Read original article ↗
AI Summary
Threat actors are actively exploiting CVE-2026-87902, a critical vulnerability in WordPress that allows unauthenticated remote code execution (RCE) under specific conditions. Exploitation requires the active theme to have a directory starting with 'page-' and a readable local PHP file such as 'pearcmd.php' on the server. Attackers are leveraging the vulnerability to write PHP web shells to temporary directories and are retrieving payloads from a GitHub repository. Multiple IP addresses have been observed conducting exploitation attempts, with the first recorded just hours after the patch was released.
AI-extracted · verify before operational use
Indicators of Compromise 13 extracted
| Type | Value | Detail |
|---|---|---|
| IP | 104[.]194[.]9[.]227 | Details → |
| IP | 43[.]250[.]53[.]42 | Details → |
| IP | 180[.]251[.]159[.]243 | Details → |
| IP | 195[.]178[.]110[.]247 | Details → |
| IP | 107[.]189[.]14[.]87 | Details → |
| IP | 45[.]61[.]184[.]170 | Details → |
| IP | 92[.]246[.]130[.]76 | Details → |
| GitHub Repo | MrG3P5/web-shell | Details → |
| Filename | pearcmd.php | Details → |
| Filename | wp-pear-rce-flag.php | Details → |
| Filename | poc87902.php | Details → |
| Filename | luci_<random>.php | Details → |
| Filename | zeta_<random>.php | Details → |