Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure

Yesterday, a critical vulnerability in WordPress was exploited by attackers mere hours after its public disclosure. The bug, identified as CVE-2026-87902, affects all versions of WordPress prior to 5.9.2 and allows an attacker to gain elevated privileges on a compromised site.

The impact of this exploit is far-reaching, with thousands of websites potentially vulnerable to unauthorized access. According to estimates, over 43% of the web runs on WordPress, making it one of the most popular content management systems (CMS) in use today. This means that hundreds of thousands of sites could be at risk of being compromised.

But what exactly is a cross-domain privilege escalation? In simple terms, it’s when an attacker uses a vulnerability to gain access not just to their own site, but also to other connected websites or services. This can happen through various means, including shared hosting environments, third-party plugins, or even social media integrations. The key takeaway here is that the attack surface of a compromised WordPress site extends far beyond its own domain.

The fact that attackers were able to exploit this vulnerability within hours of disclosure highlights the ongoing cat-and-mouse game between security researchers and malicious actors. While it’s great to see vulnerabilities being responsibly disclosed, allowing attackers to pounce on them so quickly raises questions about the timeliness of patches and updates. For site owners, this is a sobering reminder that even with the best security measures in place, there will always be a risk of compromise.

WordPress has since issued an emergency patch for affected sites, urging users to upgrade to version 5.9.2 or higher as soon as possible. However, many site owners may not have taken immediate action due to various reasons such as technical limitations or lack of awareness. This highlights the importance of regular updates and maintenance in keeping online properties secure.

For security-conscious readers, this incident serves as a stark reminder that patching vulnerabilities is just one aspect of maintaining overall system integrity. Regular backups, network segmentation, and implementing robust access controls can go a long way in mitigating potential damage from exploited vulnerabilities. By taking proactive steps to harden their defenses, site owners can reduce the risk of falling victim to similar attacks in the future.


Source: The Hacker News — 2026-09-24