WordPress patches a critical severity security vulnerability
WordPress has patched what it described as a critical severity security vulnerability that would allow an unauthenticated attacker full remote code execution (RCE) capabilities. There have already been reports of attacks in the wild. Given its popularity, WordPress has frequently been under attack , and patched another maximum severity bug allowing RCE in July. WordPress said the current hole,…
WordPress has released a security update patching a critical vulnerability that allows unauthenticated attackers to execute remote code. This bug, tracked as CVE-2026-87902, was discovered and reported by security researcher Robert Ressl. The flaw enables attackers to potentially read wp-config.php, obtain database credentials, create administrator accounts, alter forms, redirect visitors, and install persistent code.
Given WordPress's widespread use, it is often targeted, and another critical bug with RCE capabilities was addressed in July. Security experts emphasize the urgency to patch the vulnerability, as attackers have already begun exploiting the flaw shortly after the patch was released. They recommend automating updates cautiously, as insufficient verification may lead to issues.
Written by urgent.news from Computerworld's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.