Critical WordPress Vulnerabilities Expose Sites to Remote Code Execution
Article Content
- •CVE-2026-87902 allows remote code execution via local file inclusion.
- •The 'Click2Shell' vulnerability is a pre-authentication RCE flaw without a CVE.
- •Immediate patching is essential to protect WordPress sites from exploitation.
Two significant vulnerabilities affecting WordPress have been reported. The first, CVE-2026-87902, allows unauthenticated remote attackers to exploit local file inclusion leading to remote code execution. This vulnerability is due to improper validation during page-template resolution and could compromise affected websites. The second vulnerability, referred to as 'Click2Shell', is a pre-authentication remote code execution flaw but lacks a CVE identifier. Both vulnerabilities are critical, with CVE-2026-87902 published on September 22, 2026, and a proof-of-concept released on September 23, 2026. Administrators are urged to apply patches immediately to mitigate risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-76460 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Plugin4Shell: Zero-Click RCE Vulnerability in Major AI Coding Agents Plugin4Shell is a critical zero-click remote code execution vulnerability affecting four major AI coding agents: Claude Code, Codex, GitHub Copilot, and Gemini CLI. Discovered by AIR Security, this flaw allows attackers to exploit trusted plugin marketplaces by swapping legitimate plugins with malicious ones, gaining…
AI-Powered Android Malware RedHat Survives Deletion and Steals Banking Credentials A new Android banking trojan named RedHat has been discovered, featuring an AI component that allows it to adapt to changes in banking app layouts. This malware can create invisible overlays to capture user credentials and one-time passwords, effectively controlling victims' banking accounts. It is distributed through…