PULSE the living trend engine
🤖 Open Intelligence Dossier available for AI agents & citation View Markdown (.md) →
▲ Peaking Technology

Hackers start exploiting critical WordPress flaw for code execution

Hackers have begun actively exploiting a critical vulnerability in WordPress core that enables remote code execution.

7sources
8articles
5velocity
+89%since first seen
4h agofirst detected

Velocity

How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →

The brief

Recent reports from specialized security outlets outline a rapidly developing situation regarding WordPress core security. According to coverage from BleepingComputer, hackers have already started exploiting a critical flaw that allows for code execution on vulnerable servers. SecurityWeek, The Hacker News, and heise online report that WordPress has issued a patch for this specific vulnerability, which is tracked as CVE-2026-87902 and also referred to in coverage as the Click2Shell vulnerability. Additional reporting by forkast.news notes that while the core software was patched within hours of discovery, attackers had already gained unauthorized access to targeted environments. Coverage across all participating technology publications emphasizes the severe nature of the security gap.

Outlets such as Security Affairs detail how close individual WordPress installations are to remote code execution risks, while heise online highlights the mechanism by which the Click2Shell vulnerability compromises affected websites. The Hacker News points out that the flaw specifically enables code execution on some servers, creating an urgent situation for site administrators and hosting providers alike. The rapidity of the patch release is a central focus in the reporting from forkast.news, contrasting the speed of the software update with the immediate presence of malicious actors inside compromised systems. This unfolding incident builds on the perpetual challenge of securing widely deployed content management systems against zero-day and newly weaponized exploits. WordPress powers a massive share of global web infrastructure, meaning vulnerabilities affecting core files carry widespread implications for site integrity and data security.

The reporting indicates that the gap between vulnerability disclosure, patch deployment, and active exploitation by threat actors has compressed significantly, leaving little window for administrative remediation. Coverage does not yet specify the total number of websites successfully compromised or the identity of the groups orchestrating the attacks. As the situation develops, observers will be tracking further technical analysis of the CVE-2026-87902 vulnerability and its exploitation patterns. Security analysts and platform maintainers are expected to release additional guidance regarding mitigation steps for servers that have not yet applied the patch. Future updates will likely clarify the extent of the initial breaches reported by forkast.news and whether additional patches or hardening measures will be required to fully neutralize the Click2Shell exploit vector across diverse hosting environments.

Synthesized by PULSE from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 3h ago.

Quick answers

What is the name of the critical WordPress vulnerability?

Coverage identifies the vulnerability as CVE-2026-87902, also referred to as the Click2Shell vulnerability.

Which outlets are covering the exploit?

Outlets providing coverage include forkast.news, Security Affairs, heise online, SecurityWeek, The Hacker News, and BleepingComputer.

What does the vulnerability allow attackers to do?

The flaw enables remote code execution on some servers and allows attackers to compromise WordPress websites.

Coverage (8)

Topics

Related trends

◼ Archived Technology

Microsoft patches Windows and Excel

5 news sources are covering this Technology story right now — PULSE is tracking how fast it spreads.

5 sources 5 articles v 3 9d ago
\n \n \n \n \n \n \n