CyberNotablePartialDeveloping
5.3
WordPress Patches 'Click2Shell' Flaw Enabling Remote Code Execution
SecurityWeekLO·2 days ago
Threat actors have escalated from scanning to active exploitation of a critical WordPress vulnerability (CVE-2026-87902), writing webshells to disk for command execution. The flaw's widespread use makes this a high-impact supply-chain risk for sites running affected versions. Patching is urgent but adoption may lag, leaving many sites exposed.