# Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure

> **Open Intelligence Dossier** · First detected: 2026-09-24 13:20 UTC · Category: Technology

## Executive Summary
Attackers rapidly exploited a critical WordPress security flaw known as Click2Shell immediately following its public disclosure.

## Intelligence Brief
Recent reports from outlets such as BleepingComputer, SecurityWeek, Field Effect, and csoonline.com detail an active security incident involving WordPress software. Specifically, attackers began exploiting a critical severity security vulnerability within hours of its disclosure. This security weakness allows malicious actors to execute PHP directly on affected servers, creating significant risk for site administrators and hosting providers worldwide. Media coverage heavily emphasizes the speed with which malicious actors capitalized on the security gap.


SecurityWeek and BleepingComputer both report that the exploitation occurred immediately after disclosure, highlighting a shrinking window for administrators to apply defensive patches. Simultaneously, csoonline.com frames the development around the official patching of a critical severity security vulnerability by WordPress maintainers. This incident follows the standard pattern of zero-day or rapid-turnaround exploits where automated threat scanners monitor public vulnerability disclosures to target unpatched installations. Because the software under attack powers a substantial share of global web infrastructure, the immediate exploitation timeline presents acute operational challenges for website operators responsible for maintaining server integrity and applying emergency updates.


Readers and administrators should monitor ongoing coverage for additional technical details regarding attack vectors and indicators of compromise. Future reports will likely clarify whether automated botnets drove the immediate wave of exploitation or if targeted attacks accompanied the public disclosures. Furthermore, coverage does not yet specify the total volume of compromised sites, leaving open questions about the broader impact of the Click2Shell flaw that ongoing security tracking will need to address.

## Multi-Source Evidence Table
| Source Outlet | Headline | Verification URL |
|---|---|---|
| BleepingComputer | WordPress Click2Shell flaw lets hackers execute PHP on the server | [Source Link](https://news.google.com/rss/articles/CBMiswFBVV95cUxPRmxVeGJNbzJ4Sk9lamFLdlk0LTB4ekxTeFNvbmZvVjJzdWVpbUN5ZEZSSXRZX0p3b1o0LU5jaUVqVUdiNUFpdFVKaWx4M29ablZMRVVVdXRIMGY0SUxyOHhkY3VlOV9yLXRhcmFnTERiZlAzNUNnU1ptNmgxOEEwWl9aYTFSY1lTQkVkM0RTZkd2Yl9zbDQ3aldjNnZCMnNKWjhmakxGbUJ2a3dvRk05cEtIOA?oc=5) |
| SecurityWeek | Critical WordPress Vulnerability Exploited Immediately After Disclosure | [Source Link](https://news.google.com/rss/articles/CBMiowFBVV95cUxQdHYwWlB0OGx2TnM0anMyZEJNWTJGLUpWbDV0alhVWncyQXZaLWk3WUVnQ2xiWWlVVkVlX3dGazhKb0V5cTByRXJfek9ZcUNfRkZ2NmhNODZFelozN0Jua19hdktHNWhWUG82WWdSaHVfaHRmMDhmNjllNUowOFVHMTVLWjVoYUFrRUFpRHNSSDJkRzZUY0ZBM0VacU4tSXlLR2RJ?oc=5) |
| Field Effect | WordPress 7.1.1 fixes two paths to shell | [Source Link](https://news.google.com/rss/articles/CBMidEFVX3lxTE42a0NoaVdVR0JRcDBxZm03NTUwdkFYckJNT0VtajhIa1dnSGo1cm1FcnVqYng4a2FMa003RzQ0dTdKbUpjU1pPSFRmWDkwS2htZFB6NWNVSnhCc0c5aEFHSXRDd2RnQVZ5UGs2THpsR1lpNFBT?oc=5) |
| csoonline.com | WordPress patches a critical severity security vulnerability | [Source Link](https://news.google.com/rss/articles/CBMiqwFBVV95cUxOWXFzaklzNVFrVXVXVFlMUk8ySDdybTc1VkZ1YVlnbE8zeWY1clN5SDVWSmNBWjlPNHhhOTRwaXk1UG1jZG5leHdXRG1oelRyUVoyVEo1YjFYWlk3RnNGa0l0dnpMbGdqX29BSTFEZGpaZEtYNGRLQ0xtT21VWXBmakY1QTRMX09WMTdseWRwR0lLUTJPckM0aW9aRUxyNkxiTm0yQ1JtMjdudEU?oc=5) |
| BleepingComputer | WordPress Click2Shell flaw lets hackers execute PHP on the server | [Source Link](https://news.google.com/rss/articles/CBMiswFBVV95cUxPRmxVeGJNbzJ4Sk9lamFLdlk0LTB4ekxTeFNvbmZvVjJzdWVpbUN5ZEZSSXRZX0p3b1o0LU5jaUVqVUdiNUFpdFVKaWx4M29ablZMRVVVdXRIMGY0SUxyOHhkY3VlOV9yLXRhcmFnTERiZlAzNUNnU1ptNmgxOEEwWl9aYTFSY1lTQkVkM0RTZkd2Yl9zbDQ3aldjNnZCMnNKWjhmakxGbUJ2a3dvRk05cEtIONIBuAFBVV95cUxPZEphYi02UGhtd0RlZWZlc0NyVXIxTklGc2tuQTNDZWZoN29EV3N5QUN0T3hfdHk5MWdLMHR0NFpuUTN1RF9NYlZDQTY5V2pEUnpIeFJYbXBnWnQ3WHRlYWJQWkluckJmbFBWX3JPb3VZNC01UFlKWTQ4a3NHVU9kbzh3Y2pTZjFZaVZ4VzNCMEt0MmV2Z1FVaVBBS3VhVTJ) |
| SecurityWeek | Critical WordPress Vulnerability Exploited Immediately After Disclosure | [Source Link](https://news.google.com/rss/articles/CBMiowFBVV95cUxQdHYwWlB0OGx2TnM0anMyZEJNWTJGLUpWbDV0alhVWncyQXZaLWk3WUVnQ2xiWWlVVkVlX3dGazhKb0V5cTByRXJfek9ZcUNfRkZ2NmhNODZFelozN0Jua19hdktHNWhWUG82WWdSaHVfaHRmMDhmNjllNUowOFVHMTVLWjVoYUFrRUFpRHNSSDJkRzZUY0ZBM0VacU4tSXlLR2RJ0gGoAUFVX3lxTE1GRWFqSGpJR3hkS285REVKUTNnbjRfZ3dzQXR1LXpmS0JmTldtQXg2Uk85dGlReTlNNnJCUS1DR2dzdG5rWGVpb0lvQjZqTDczUFc2bDd5ZzR5RDMwMDVmbjBRUTZQOUpFdUYtbEd0LUE0RkFlMFpudzZ5VjdLcmV6LXVvaTFDZzlkQkQtZVIwV3hHQXVhY2lzR1RERDRtbWkyenBwYXROTg?oc=5) |

---
*Canonical Source: https://pulse.byoviral.com/trend/2026-09-24/attackers-exploit-wordpress-cve-2026-87902-within-hours-of-disclosure*
