Follow the latest coverage, related explainers and connected technology stories.
Attackers have begun exploiting CVE-2026-87902 in WordPress to write PHP files to disk and run shell commands when those files are accessed, just hours after the patch was released. Site administrators are advised to update to version 7.1.2 and review logs immediately.