# Critical WordPress Vulnerability Exploited Immediately After Disclosure

DevFeed: [Critical WordPress Vulnerability Exploited Immediately After Disclosure](<https://devfeed.tech/articles/critical-wordpress-vulnerability-exploited-immediately-after-disclosure-59262.md>)

Original publisher: [Read original article](<https://www.securityweek.com/critical-wordpress-vulnerability-exploited-immediately-after-disclosure/>)

Author: Ionut Arghire

Published: 2026-09-24T07:12:26Z

Content type: news

Language: en

Sources: [SecurityWeek](<https://devfeed.tech/sources/securityweek.md>)

Topics: [Exploit](<https://devfeed.tech/topics/exploit.md>), [Security](<https://devfeed.tech/topics/security.md>), [WordPress](<https://devfeed.tech/topics/wordpress.md>), [PHP](<https://devfeed.tech/topics/php.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [Server](<https://devfeed.tech/topics/server.md>)

Tags: [critical](<https://devfeed.tech/tags/critical.md>), [cve](<https://devfeed.tech/tags/cve.md>), [docker](<https://devfeed.tech/tags/docker.md>), [exploited](<https://devfeed.tech/tags/exploited.md>), [featured](<https://devfeed.tech/tags/featured.md>), [path-traversal](<https://devfeed.tech/tags/path-traversal.md>), [php](<https://devfeed.tech/tags/php.md>), [releases](<https://devfeed.tech/tags/releases.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [wordpress](<https://devfeed.tech/tags/wordpress.md>)

## AI overview

Security researchers report that CVE-2026-87902, a critical path traversal vulnerability in WordPress page-template resolution, was exploited within hours of disclosure and escalated to active compromises. Under specific server and theme conditions, unauthenticated attackers could achieve remote code execution. WordPress fixed the issue in version 7.1.2 and backported the fix to older releases.

## Source excerpt

Tracked as CVE-2026-87902, the path traversal flaw allows remote, unauthenticated attackers to execute arbitrary code. The post Critical WordPress Vulnerability Exploited Immediately After Disclosure appeared first on SecurityWeek.