bleeping-computer · Crawled Sep 24, 2026

Hackers start exploiting critical WordPress flaw for code execution

7 IoCs
Read original article ↗

AI Summary

Threat actors are actively exploiting a critical unauthenticated path traversal vulnerability in WordPress, tracked as CVE-2026-87902, to achieve remote code execution under specific conditions. The exploitation involves writing malicious PHP files to the server's filesystem, which execute shell commands when accessed. Initial activity began within hours of the patch release, with reconnaissance escalating to active payload delivery, including file writing to /tmp and /var/tmp directories using attacker-controlled content.

AI-extracted · verify before operational use

Indicators of Compromise 7 extracted

Type Value Detail
IP 169[.]58[.]48[.]193 Details →
IP 169[.]58[.]48[.]195 Details →
IP 2001:df1:e8c0::106b Details →
Filename wp-pear-rce-flag.php Details →
Filename poc87902.php Details →
Filename luci_<random>.php Details →
Filename zeta_<random>.php Details →