• Hackers are targeting a critical WordPress flaw, so be on your gu

    From TechnologyDaily@1337:1/100 to All on Thursday, September 24, 2026 15:45:20
    Hackers are targeting a critical WordPress flaw, so be on your guard

    Date:
    Thu, 24 Sep 2026 14:30:00 +0000

    Description:
    Mitigations and a patch are already available but given the severity of the WordPress flaw, immediate patching is recommended.

    FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter WordPress Core flaw
    CVE202687902 (path traversal, 8.1 severity) enables PHP file inclusion and possible RCE Patch released in v7.1.2 and backported to 4.7+; exploitation began within hours, now widespread Admins must urgently update; interim mitigations include blocking traversal sequences and disabling risky ARP/PHP settings Hackers are actively exploiting a high severity vulnerability in WordPress that can lead to full website takeover, researchers are saying. A patch is available, and WordPress users are urged to upgrade immediately or risk losing access to their assets.

    Discovered by security researcher Robert Ressl, the vulnerability in question is tracked as CVE-2026-87902. It is an 8.1/10 (high severity) unauthenticated path traversal flaw affecting WordPress Core. According to WordPress itself, as well as the National Vulnerability Database, the bug can lead to local PHP file inclusion and, in certain scenarios, remote code execution (RCE). "An unauthenticated attacker can make get_page_template() page-template
    resolution include a chosen readable local .php file outside the active theme directories," it was said in the official security advisory. Latest Videos From TechRadar Watch full video here: Achieving RCE WordPress is the worlds number one website hosting and builder platform , powering more than half of all websites active on the internet right now. However, that doesnt mean all of them are susceptible to RCE. Only websites ticking these boxes are at
    risk:

    Sites with parent or child themes that have a top-level directory with a name starting with page- (for example, page-templates). You may like Two major security flaws are affecting more than six million WordPress websites Experts warn millions of WordPress websites could be at risk following reveal of worrying bugs Third-party WooCommerce plugin hits WordPress sites with PHP backdoor abusing recently patched vulnerability

    Threat actors must target a local .PHP file that exists and is readable by
    the web server

    The web server account must be able to read the included file (for example, pearcmd.php, if PHPs register_argc_argv setting is active) Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get
    all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting
    your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.

    WordPress said that both the official PHP image for Docker, and the default cPanel configuration, are affected (users must be running a PHP version
    before 8.5, though).

    The issue was fixed in version 7.1.2, which is now available for download. Fixes were also backported to older versions up to 4.7. Releases before 4.8 are not supported, it was said, and will not be getting a fix. Attacking vulnerable websites Wordpress security company Patchstack said the first exploitation attempts started roughly five hours after the patch was
    released, and these were primarily reconnaissance efforts. In the hours to follow, malicious activity increased tenfold, it was said, as crooks started attempting to deliver malicious payloads to vulnerable websites, as well.
    What to read next Linux users beware CISA flags three major security issues you need to patch right now CISA warns hackers are exploiting max severity GitLab flaw urges all businesses to patch immediately Watch out TP-Link
    Tapo Camera vulnerabilities could let hackers spy inside homes, so patch now

    When this post first went up, every request we had seen was reconnaissance against harmless core files, Patchstack said. That is no longer true. Attackers are now including pearcmd.php and using it to write PHP files to disk, and public scanning tooling for this CVE is in circulation.

    At first, Patchstack said the attacks were coming from a handful of IP addresses, and advised website admins to simply block them. However, the attacks have now become rather widespread, meaning blocking individual addresses is no longer a viable strategy. They urge everyone to apply the patch without delay:

    The first evening came from a small cluster of addresses. It is now spread across a few hundred, so blocklisting individual sources is not a strategy. The heaviest talkers at the time of writing:

    43.250.53.42

    180.251.159.243

    195.178.110.247

    107.189.14.87

    45.61.184.170

    92.246.130.76

    The file write attempts specifically come from a much smaller subset of those addresses, which is the usual pattern of a few operators acting on results that a much larger scanning population produced.

    Those that cannot update immediately should reject traversal sequences in the pagename parameter, Patchstack added. A real page slug never contains one, they added, meaning it can be blocked without affecting normal traffic. Furthermore, disabling register_argc_argv does not fix the inclusion but it does break the pearcmd chain, which is the difference between an information leak and code execution.

    Via BleepingComputer The best antivirus for all budgets Our top picks, based on real-world testing and comparisons

    Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.



    ======================================================================
    Link to news story: https://www.techradar.com/pro/security/hackers-are-targeting-a-critical-wordpr ess-flaw-so-be-on-your-guard


    --- Mystic BBS v1.12 A49 (Linux/64)
    * Origin: tqwNet Technology News (1337:1/100)