Tech article

Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure - The Hacker News

Publisher description: Attackers are exploiting WordPress CVE-2026-87902 to include pearcmd.php and write PHP files when specific theme and server conditions are met.

NewsAPI | Sep 24, 2026 | The Hacker News

Automated excerpt

"An unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable local . php file outside the active theme directories," WordPress said in an advisory released two days ago. A chosen local . php target file exists on the server and is readable by the web server account. (e. g. , pearcmd. php). These requests include the local PHP file /usr/local/lib/php/pearcmd. php, writing a file to /tmp/, and then including a PHP upload script hosted on GitHub ("raw. githubusercontent[. ]com/MrG3P5/web-shell/refs/heads/main/uploader. php").

Selected automatically from source text; not independently written or fact-checked. Read the original for full context.

Read the original article

More tech news