WordPress 7.1.1 fixes Click2Shell, which can force theme installs from crafted links and was chained with a theme flaw for code execution.
Hackers are actively exploiting CVE-2026-87902, a critical WordPress flaw that can lead to remote code execution. Here’s what admins should do.
WordPress fixes a critical unauthenticated path traversal flaw that can load local PHP files and, on some servers, enable code execution.
WordPress 7.1.2 security release fixes a critical flaw (CVE-2026-87902) letting unauthenticated attackers load local PHP files and run code.
A high-severity SQL injection flaw in All-in-One WP Migration and Backup — installed on more than 5 million WordPress sites — has a weaponized proof-of-concept exploit circulating in ...
Technical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed 'Click2Shell' that affects the platform's Core component ...
Threat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to exploiting the flaw to write files to disk that execute shell commands when accessed. Initial attack traffic was ...