{
  "id": 9566993,
  "title": "Hackers are targeting a critical WordPress flaw, so be on your guard",
  "url": "https://urgent.news/2026/09/24/hackers-are-targeting-a-critical-wordpress-flaw-so-be-on-your-guard",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-24T14:30:00.000Z",
  "source": {
    "name": "TechRadar",
    "slug": "techradar",
    "url": "https://www.techradar.com/pro/security/hackers-are-targeting-a-critical-wordpress-flaw-so-be-on-your-guard"
  },
  "original_language": "en",
  "account": "A critical WordPress flaw that enables PHP file inclusion and potentially remote code execution (RCE) is being actively targeted by hackers, putting millions of websites worldwide at risk. The flaw, tracked as CVE-2026-87902, has a high severity rating of 8.1 out of 10. Researchers discovered the vulnerability eight months ago, but attackers have only recently begun exploiting it en masse.\n\nWordPress Core, which powers more than half of all websites on the internet, is affected by the flaw. The vulnerability allows unauthenticated attackers to include local PHP files outside the active theme directories, potentially leading to the execution of malicious code on the targeted website. To exploit the flaw, attackers must target a local PHP file that exists and is readable by the web server, and the web server must be configured to allow file inclusion.\n\nWordPress has released a patch (v7.1.2) to address the flaw, and it is recommended that all website administrators update their WordPress installations immediately. However, administrators can also implement interim mitigations, such as blocking traversal sequences in the pagename parameter and disabling the register_argc_argv setting, to further reduce the risk of exploitation. Websites with parent or child themes that have a top-level directory with a name starting with 'page-' are particularly vulnerable to the flaw.",
  "summary": "Mitigations and a patch are already available but given the severity of the WordPress flaw, immediate patching is recommended.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}