Attackers began exploiting a critical WordPress flaw within hours of the fix. The bug, CVE-2026-87902, can let an attacker with no login run code on a website’s server. It only works under certain conditions.
Source: [TNW](https://thenextweb.com/news/wordpress-flaw-cve-2026-87902-exploited)