Skip to main content

Share story

Security

Attackers exploit critical WordPress flaw to plant command-executing files

Attackers exploit critical WordPress flaw to plant command-executing files Image: Primary
Attackers are exploiting a critical WordPress flaw to write files that can execute shell commands when accessed, BleepingComputer reports, citing security firm Patchstack. The activity has advanced from probing vulnerable sites to attempts to deliver payloads, with related traffic increasing tenfold. The flaw, CVE-2026-87902, can let an unauthenticated attacker make WordPress load a readable PHP file outside the active theme directory. Remote code execution requires particular theme and server conditions. WordPress patched the issue in version 7.1.2 and backported fixes through version 4.7; releases before 4.6 will not receive a fix.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from BleepingComputer and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Products
Products

Bird.com raises $450 million in JPMorgan-led debt financing

Bird.com, a customer messaging company, raised $450 million in debt financing led by JPMorgan Chase & Co., Bloomberg reported. The company is seeking to return cash to its investors and employees. The transaction adds debt capital...

Capital Infrastructure
Capital Infrastructure

Hubble Network raises $200 million for satellite Bluetooth network

Satellite startup Hubble Network raised $200 million in a new funding round, Bloomberg reported, taking its valuation to $1.6 billion. The company is working on a network of spacecraft intended to provide global Bluetooth connecti...

Security Infrastructure
Security Infrastructure

Analysis identifies two flaws behind exploited MikroTik router takeover chain

CERT Polska has identified the two RouterOS SSH flaws behind a previously reported attack that can give intruders administrative control of exposed MikroTik routers without completing authentication. One flaw lets a connection rea...

Capital Robotics
Capital Robotics

Ondas acquires three Israeli defense technology firms for $56 million

Ondas is acquiring Insignito, Ottopia Defense and Caribou Labs for an initial $56 million in cash or stock, CTech reports. The deals could add up to $32 million in payments tied to performance targets through 2028 and bring 37 emp...

Robotics Capital
Robotics Capital

Tekever reaches first close of funding round targeting $580 million

Portuguese surveillance drone developer Tekever has reached the first close of a funding round targeting $580 million, Bloomberg reports. The company is seeking acquisitions following that close. The $580 million figure is the tar...

Robotics Capital
Robotics Capital

Helicon raises $16 million to automate carbon fiber manufacturing

Helicon Industries has emerged from stealth with $16 million in seed funding led by AlleyCorp. The Los Angeles startup is building automated systems to make carbon fiber parts at higher volumes for customers in fields including dr...