PULSE the living trend engine
🤖 Open Intelligence Dossier available for AI agents & citation View Markdown (.md) →
◼ Archived Technology

Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure

Attackers rapidly exploited a critical WordPress security flaw known as Click2Shell immediately following its public disclosure.

4sources
6articles
3velocity
4d agofirst detected

Velocity

How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →

The brief

Recent reports from outlets such as BleepingComputer, SecurityWeek, Field Effect, and csoonline.com detail an active security incident involving WordPress software. Specifically, attackers began exploiting a critical severity security vulnerability within hours of its disclosure. This security weakness allows malicious actors to execute PHP directly on affected servers, creating significant risk for site administrators and hosting providers worldwide. Media coverage heavily emphasizes the speed with which malicious actors capitalized on the security gap.

SecurityWeek and BleepingComputer both report that the exploitation occurred immediately after disclosure, highlighting a shrinking window for administrators to apply defensive patches. Simultaneously, csoonline.com frames the development around the official patching of a critical severity security vulnerability by WordPress maintainers. This incident follows the standard pattern of zero-day or rapid-turnaround exploits where automated threat scanners monitor public vulnerability disclosures to target unpatched installations. Because the software under attack powers a substantial share of global web infrastructure, the immediate exploitation timeline presents acute operational challenges for website operators responsible for maintaining server integrity and applying emergency updates.

Readers and administrators should monitor ongoing coverage for additional technical details regarding attack vectors and indicators of compromise. Future reports will likely clarify whether automated botnets drove the immediate wave of exploitation or if targeted attacks accompanied the public disclosures. Furthermore, coverage does not yet specify the total volume of compromised sites, leaving open questions about the broader impact of the Click2Shell flaw that ongoing security tracking will need to address.

Synthesized by PULSE from the headlines below under a strict no-invention contract. ✓ fact-checked: unsupported claims removed (79% supported) Updated 1d ago.

Quick answers

What is the WordPress Click2Shell flaw?

Coverage states it is a critical severity security vulnerability that allows hackers to execute PHP on the server.

Which WordPress version addresses the vulnerability?

According to Field Effect, WordPress 7.1.1 fixes two paths to shell access.

How quickly was the flaw exploited?

SecurityWeek and other outlets report that the vulnerability was exploited immediately after disclosure, within hours.

Coverage (6)

Topics

Related trends

\n \n \n \n \n \n \n