Skip to content
ThreatCluster

Critical WordPress Vulnerabilities Expose Sites to Remote Code Execution

First seen 23 Sep 2026, 10:59 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 23, 2026 at 11:57 UTC
  • CVE-2026-87902 allows remote code execution via local file inclusion.
  • The 'Click2Shell' vulnerability is a pre-authentication RCE flaw without a CVE.
  • Immediate patching is essential to protect WordPress sites from exploitation.

Two significant vulnerabilities affecting WordPress have been reported. The first, CVE-2026-87902, allows unauthenticated remote attackers to exploit local file inclusion leading to remote code execution. This vulnerability is due to improper validation during page-template resolution and could compromise affected websites. The second vulnerability, referred to as 'Click2Shell', is a pre-authentication remote code execution flaw but lacks a CVE identifier. Both vulnerabilities are critical, with CVE-2026-87902 published on September 22, 2026, and a proof-of-concept released on September 23, 2026. Administrators are urged to apply patches immediately to mitigate risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-16
CVE-2026-76460 published
Cisco Identity Services Engine API Authentication Bypass vulnerability disclosed, affecting multiple versions.
Itsc.Cuhk.Edu.Hk
2026-09-22
CVE-2026-87902 published
Critical WordPress vulnerability disclosed, allowing unauthenticated remote code execution.
Itsc.Cuhk.Edu.Hk
2026-09-23
PoC for CVE-2026-87902 released
Public proof-of-concept code for the critical WordPress vulnerability made available.
Itsc.Cuhk.Edu.Hk

More articles in this cluster (2)

Following this threat?

Track CVE-2026-76460 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed