Critical WordPress RCE CVE-2026-87902 reproduced for $4.93 with an AI agent

evilsocket · x · 2026-09-24

Security researcher pruvadev has published a verified reproduction of CVE-2026-87902, a newly disclosed WordPress Core vulnerability: an unauthenticated path traversal in page-template resolution that can conditionally lead to remote code execution, rated Critical (CWE-98).

Key facts:

The author warns to run it only in a VM or disposable container since it exploits a real vulnerability.

Original post →

More from coding & agent

coding & agent channel →