보안 최초 · 갱신
워드프레스 취약점 공개 직후 공격에 악용
인증 없이 PHP 파일을 불러 원격 코드 실행으로 이어질 수 있는 CVE-2026-87902다.
왜 중요한가
사이트 운영자가 지원 브랜치에 맞는 수정판을 적용하지 않으면 인증 없는 원격 코드 실행 위험에 노출될 수 있다.
30초 요약
공격자는 경로 조작으로 서버의 로컬 PHP 파일을 불러 실행할 수 있다. WordPress는 수정판을 배포했지만, 보안 매체들은 공개 뒤 실제 공격이 시작됐다고 보도했다.
무슨 일이 있었나
취약점은 페이지 템플릿을 찾는 과정에서 공격자가 지정한 읽을 수 있는 로컬 PHP 파일이 포함될 수 있는 경로 조작 문제다. WordPress는 9월 22일 버전 7.1.2와 지원 중인 다른 브랜치용 수정판을 배포했다. BleepingComputer와 The Hacker News는 공개 직후 이 취약점을 이용한 공격이 시작됐다고 보도했다.
타임라인
WordPress가 취약점 수정판을 배포했다고 The Hacker News가 보도했다.
WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some ServersBleepingComputer가 공격자들의 취약점 악용을 보도했다.
Hackers start exploiting critical WordPress flaw for code executionThe Hacker News와 SecurityWeek가 공개 직후의 실제 악용을 보도했다.
Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure
출처 3곳 · 기사 21건
- The Hacker NewsElementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link
- BleepingComputerShinyHunters hacked Clop leak site using Grav CMS path traversal flaw
- BleepingComputerElementor WordPress flaw lets attackers create admin accounts
- The Hacker NewsRoundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild
- SecurityWeekRoundcube Webmail Vulnerability in Attackers’ Crosshairs
- Hacker NewsSourcehut account takeover via build logs (XSS in ansi2html)
- Hacker NewsDiscovering and exploiting a remote code execution vulnerability in OpenCode
- Hacker NewsCVE-2026-91766: PHP had the redirect credential leak curl fixed in 2018
- Hacker NewsMistral Vibe Shell Permission Bypass Leading to Arbitrary Code Execution
- SecurityWeekCritical WordPress Vulnerability Exploited Immediately After Disclosure
- The Hacker NewsAttackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure
- BleepingComputerHackers start exploiting critical WordPress flaw for code execution
- The Hacker NewsNew cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control
- Hacker NewsNext.js 16.3.6 fixes critical ImageResponse RCE (CVE-2026-94545)
- The Hacker NewsCritical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input
- The Hacker NewsWordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers
- Hacker NewsA WordPress vulnerability scored 9.2/10 is present in all versions since 2016
- The Hacker NewsSharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE
- SecurityWeekWordPress Patches ‘Click2Shell’ Vulnerability
- The Hacker NewsWordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session
- BleepingComputerWordPress Click2Shell flaw lets hackers execute PHP on the server