Hackers start exploiting critical WordPress flaw for code execution
CVE-2026-87902 allows remote attackers to write arbitrary files to affected WordPress sites

Key Takeaways
- CVE-2026-87902 is a critical WordPress vulnerability allowing remote code execution.
- Attackers can write arbitrary files to the server disk, enabling shell command execution.
- Exploitation has shifted from scanning to active weaponization.
- Unauthenticated attackers may exploit the flaw without prior access.
- Immediate patching and web application firewall rules are recommended.
Related Security News

Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
The maintainers of the official MCP Python SDK disclosed a security vulnerability that could allow a malicious server to trick applications into divulging OAuth credentials. The issue affects the handling of client secrets, authorization codes, and PKCE proof keys when communicating with token endpoints.

One Packet Can Crash OT Servers in Industrial Sectors
A high-severity zero-day vulnerability in the TDengine time-series database allows a single malformed packet to crash OT servers, potentially disrupting industrial, IoT, energy, and automotive operations. Details regarding exploitation status and remediation remain limited.



