# Attackers exploit critical WordPress flaw to plant command-executing files

_Published Wednesday, September 23, 2026 at 4:02 PM EDT · Security · Latest · Tier 1 — Major_

![Attackers exploit critical WordPress flaw to plant command-executing files — Primary](https://www.bleepstatic.com/content/hl-images/2025/11/03/WordPress.jpg)

Attackers are exploiting a critical WordPress flaw to write files that can execute shell commands when accessed, BleepingComputer reports, citing security firm Patchstack. The activity has advanced from probing vulnerable sites to attempts to deliver payloads, with related traffic increasing tenfold.

The flaw, CVE-2026-87902, can let an unauthenticated attacker make WordPress load a readable PHP file outside the active theme directory. Remote code execution requires particular theme and server conditions. WordPress patched the issue in version 7.1.2 and backported fixes through version 4.7; releases before 4.6 will not receive a fix.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/hackers-start-exploiting-critical-wordpress-flaw-for-code-execution/)

---
Canonical: https://techandbusiness.org/newswire/b9FDoFr5E132WJcf5JFn-H
Published: 2026-09-23T20:02:06.284Z
Story chronology: 2026-09-23T18:31:22.000Z
Retrieved: 2026-09-23T21:27:09.496Z
Publisher: Tech & Business (techandbusiness.org)
