Critical WordPress Vulnerability CVE-2026-87902 Under Active Exploitation for Remote Code Execution
Threat Actors Shift from Reconnaissance to Delivering Payloads That Write Shell-Command Scripts to Disk Cybersecurity researchers report that threat actors have escalated attacks targeting a critical path traversal vulnerability in WordPress, designated as CVE-2026-87902. What began as initial reconnaissance probing shortly after the patch release…