Critical Vulnerability Identified in WordPress: Urgent Action Required
Websites utilizing WordPress versions ranging from 4.7.0 to 7.1.1 are currently imperiled by a significant vulnerability designated as CVE-2026-87902.
This flaw facilitates unauthorized arbitrary code execution on the web server, prompting immediate updates following the release of a patch on September 22.
Notably, exploit attempts were reported within mere hours of the patch’s availability, underscoring the urgency for organizations to upgrade their systems without delay.
This vulnerability enables attackers to incorporate an arbitrary PHP file into the server, contingent on the file’s prior existence on the targeted machine.
Under specific configurations of WordPress and PHP, this scenario can culminate in arbitrary code execution, leading many cybersecurity publications to categorize CVE-2026-87902 as a remote code execution vulnerability.
The exclusive remedy for this issue is the installation of the most recent WordPress version; for the majority of users, this entails upgrading to version 7.1.2 or later.
Updates have been disseminated across all active branches, and WordPress has provided a comprehensive table of patched versions and affected data on its GitHub platform.
A security researcher has shared supplementary hardening strategies that should complement, rather than replace, the essential patch.
In light of the post-attack landscape, The Hacker News has disclosed IP addresses and PHP filenames associated with the exploits, indicating potential compromises of WordPress instances.
Kaspersky further advocates for robust centralized vulnerability management systems to mitigate risks, given the rapid onset of exploit attempts following the patch release.
This disclosure follows approximately five months after another severe vulnerability, CVE-2026-3854, was uncovered in GitHub by Wiz researchers, rating a critical CVSS score of 8.7.
This particular flaw impacted GitHub.com as well as GitHub Enterprise Server, including Enterprise Cloud deployments utilizing Data Residency or the Enterprise Managed Users feature.
Wiz reported this issue to GitHub on March 4, with GitHub.com promptly patched within six hours, while updates for Enterprise Server were released by March 10.
However, nearly eight weeks later, 88% of Enterprise Server instances remained unprotected, illustrating that the timeline for implementing patches can extend well beyond the initial fix.
The GitHub vulnerability exploited an injection flaw within an internal X-Stat header, where git push options were copied directly into the header without appropriate sanitation of semicolons.
This exploitation sequence necessitated three injection attempts, with GitHub asserting no evidence of real-world exploitation had been discovered.
This finding, amongst the inaugural critical vulnerabilities identified in closed-source binaries via AI-enhanced tools, was achieved using Wiz’s IDA MCP for automated reverse engineering.
GitHub’s Chief Information Security Officer, Alexis Wales, described the finding as uncommon, which garnered one of the highest Bug Bounty rewards issued.

However, the Kaspersky article omits vital details regarding the number of unpatched sites or any confirmed compromises beyond the publicly available attack indicators.
Source link: Technobezz.com.



