Security News Hackers start exploiting critical WordPress flaw for code execution BleepingComputer Daniel Bender 23 Sep 2026 Share Threat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to exploiting the flaw to write files to disk that execute shell commands when accessed.