{
  "id": 9633661,
  "title": "WordPress patches a critical severity security vulnerability",
  "url": "https://urgent.news/2026/09/24/wordpress-patches-a-critical-severity-security-vulnerability",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-24T21:17:05.000Z",
  "source": {
    "name": "Computerworld",
    "slug": "computerworld",
    "url": "https://www.computerworld.com/article/4226366/wordpress-patches-a-critical-severity-security-vulnerability-2.html"
  },
  "original_language": "en",
  "account": "WordPress has released a security update patching a critical vulnerability that allows unauthenticated attackers to execute remote code. This bug, tracked as CVE-2026-87902, was discovered and reported by security researcher Robert Ressl. The flaw enables attackers to potentially read wp-config.php, obtain database credentials, create administrator accounts, alter forms, redirect visitors, and install persistent code. Given WordPress's widespread use, it is often targeted, and another critical bug with RCE capabilities was addressed in July. Security experts emphasize the urgency to patch the vulnerability, as attackers have already begun exploiting the flaw shortly after the patch was released. They recommend automating updates cautiously, as insufficient verification may lead to issues.",
  "summary": "WordPress has patched what it described as a critical severity security vulnerability that would allow an unauthenticated attacker full remote code execution (RCE) capabilities. There have already been reports of attacks in the wild. Given its popularity, WordPress has frequently been under attack , and patched another maximum severity bug allowing RCE in July. WordPress said the current hole,…",
  "key_points": [
    "WordPress releases patch for critical RCE vulnerability CVE-2026-87902",
    "Unauthenticated attackers can exploit flaw to read wp-config.php and create admin accounts",
    "Security experts warn of immediate exploitation and advise cautious automated updates"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}