Web_Logo
Remote Support
Security Alert: WordPress Flaw Under Active Attack
Home » Security Alerts  »  Security Alert: WordPress Flaw Under Active Attack

Security Alert: WordPress Flaw Under Active Attack

A critical WordPress vulnerability is being actively exploited by attackers within hours of being disclosed, putting business websites built on WordPress at risk of full compromise.

  • What it is: A critical flaw (CVE-2026-87902, rated 9.2 out of 10 for severity) in WordPress's core page template system lets an attacker run their own code on a website without needing a username or password.
  • Who is affected: WordPress sites running a theme with a "page-" style template folder, particularly any site that has not yet been updated to the latest core release.
  • What the risk is: Attackers are already using the flaw to plant hidden files and web shells on compromised sites, giving them ongoing access to deface the site, steal data, or use it to attack other targets.
  • What to do: Update WordPress to the latest version (7.1.2, 7.0.6, 6.9.9 or 6.8.10) as soon as possible, and have your web developer or IT provider check the server for unfamiliar files.

If your business website runs on WordPress, we recommend confirming it has been updated in the past few days and having it checked for signs of compromise.

Source: The Hacker News