워드프레스의 CVE-2026-87902 취약점이 공개된 지 몇 시간 만에 해커들에 의해 악용되고 있다.
워드프레스의 심각한 보안 결함인 CVE-2026-87902가 공개된 이후, 해커들이 이를 적극적으로 악용하고 있다. 이 취약점은 CVSS 점수 9.2를 받았으며, 인증되지 않은 공격자가 원격 코드 실행(RCE)을 수행할 수 있게 해준다. 공격자는 get_page_template() 함수의 페이지 템플릿 해석을 이용해 선택한 읽을 수 있는 로컬 .php 파일을 포함할 수 있다.
Attackers are exploiting the WordPress CVE-2026-87902 vulnerability within hours of its disclosure.
The critical security flaw in WordPress, CVE-2026-87902, is being actively exploited by threat actors within hours of its public disclosure. This vulnerability has a CVSS score of 9.2 and could allow unauthenticated attackers to achieve remote code execution (RCE). By leveraging the get_page_template() function, attackers can include a chosen readable local .php file.