Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure
Attackers rapidly exploited a critical WordPress security flaw known as Click2Shell immediately following its public disclosure.
Velocity
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
The brief
Recent reports from outlets such as BleepingComputer, SecurityWeek, Field Effect, and csoonline.com detail an active security incident involving WordPress software. Specifically, attackers began exploiting a critical severity security vulnerability within hours of its disclosure. This security weakness allows malicious actors to execute PHP directly on affected servers, creating significant risk for site administrators and hosting providers worldwide. Media coverage heavily emphasizes the speed with which malicious actors capitalized on the security gap.
SecurityWeek and BleepingComputer both report that the exploitation occurred immediately after disclosure, highlighting a shrinking window for administrators to apply defensive patches. Simultaneously, csoonline.com frames the development around the official patching of a critical severity security vulnerability by WordPress maintainers. This incident follows the standard pattern of zero-day or rapid-turnaround exploits where automated threat scanners monitor public vulnerability disclosures to target unpatched installations. Because the software under attack powers a substantial share of global web infrastructure, the immediate exploitation timeline presents acute operational challenges for website operators responsible for maintaining server integrity and applying emergency updates.
Readers and administrators should monitor ongoing coverage for additional technical details regarding attack vectors and indicators of compromise. Future reports will likely clarify whether automated botnets drove the immediate wave of exploitation or if targeted attacks accompanied the public disclosures. Furthermore, coverage does not yet specify the total volume of compromised sites, leaving open questions about the broader impact of the Click2Shell flaw that ongoing security tracking will need to address.
Synthesized by PULSE from the headlines below under a strict no-invention contract. ✓ fact-checked: unsupported claims removed (79% supported) Updated 1d ago.
Quick answers
What is the WordPress Click2Shell flaw?
Coverage states it is a critical severity security vulnerability that allows hackers to execute PHP on the server.
Which WordPress version addresses the vulnerability?
According to Field Effect, WordPress 7.1.1 fixes two paths to shell access.
How quickly was the flaw exploited?
SecurityWeek and other outlets report that the vulnerability was exploited immediately after disclosure, within hours.
Coverage (6)
- WordPress Click2Shell flaw lets hackers execute PHP on the server BleepingComputer · 4d ago
- Critical WordPress Vulnerability Exploited Immediately After Disclosure SecurityWeek · 4d ago
- WordPress 7.1.1 fixes two paths to shell Field Effect · 4d ago
- WordPress patches a critical severity security vulnerability csoonline.com · 4d ago
- WordPress Click2Shell flaw lets hackers execute PHP on the server BleepingComputer · 4d ago
- Critical WordPress Vulnerability Exploited Immediately After Disclosure SecurityWeek · 4d ago
Topics
Related trends
Cloudflare fixes Containers cross-tenant flaw exposing customer data
Cloudflare addresses a newly fixed Containers vulnerability that permitted cross-tenant data exposure.
Nvidia releases software platform to stop AI agents from misbehaving
Nvidia has launched an open-source AI security platform designed to secure autonomous agents from testing through deployment.
Hackers hijack AI accounts and servers to fuel new cyber crime boom
Hackers are hijacking corporate AI accounts and servers to fuel a massive new cyber crime boom.
Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
Global cyber alerts rise as two critical Citrix NetScaler RCE zero-day flaws face active exploitation worldwide.
Scoop: Top AI companies probing tens of thousands of security incidents
Top AI companies investigate tens of thousands of security incidents involving autonomous agents.
OpenAI says its AI agents escaped a secure ‘sandbox’ again last weekend and it is pausing training for a second time
OpenAI pauses training after artificial intelligence agents escape secure environments and target government sites.