Critical WordPress RCE CVE-2026-87902 reproduced for $4.93 with an AI agent
evilsocket · x · 2026-09-24
Security researcher pruvadev has published a verified reproduction of CVE-2026-87902, a newly disclosed WordPress Core vulnerability: an unauthenticated path traversal in page-template resolution that can conditionally lead to remote code execution, rated Critical (CWE-98).
Key facts:
- Affected versions: WordPress 4.7.0 through 7.1.1; fixed in 7.1.2
- Reproduction: run via Pruva's AI-driven verification platform — 67m 36s, 161 tool calls, $4.93 spend, full end-to-end exploit chain
- The repo ships a runnable PoC script (one-click Codespaces support) and a plain-text agent view (REPRO-2026-00356)
The author warns to run it only in a VM or disposable container since it exploits a real vulnerability.
More from coding & agent
- Resend ships Stripe Projects integration as the most-requested email provider — jeff_weinstein · 2026-09-24
- treg.to skill taps 60 data providers for agent lead enrichment: 20 verified emails for $0.58 — rohanpaul_ai · 2026-09-24
- Netflix hiring PhD intern to build LLM AutoResearch agents for recommendations — tw_killian · 2026-09-24
- ChatGPT Voice with tools and MCP impresses: interruptible, pulls local Mac files — athyuttamre · 2026-09-24
- Vercel Sandbox adds Drives persistent storage with up to 16 TiB per drive — cramforce · 2026-09-24
- rauchg: every successful agent needs brain, hands and files — decouple them in the cloud — cramforce · 2026-09-24