> ## Content Index
> Fetch the complete content index at: https://www.thecybersignal.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# WordPress Triple: CVE-2026-87902 Actively Exploited Within Hours + Comment2Shell + Click2Shell
- URL: https://www.thecybersignal.com/wordpress-triple-cve-2026-87902-comment2shell-click2shell-2026/
- Published: 2026-09-20T13:00:00.000Z
- Updated: 2026-10-06T06:38:37.000Z
- Description: Three WordPress-core flaws landed in one week, and one of them, CVE-2026-87902, was exploited within hours of disclosure. Comment2Shell and Click2Shell round out the set. WordPress 7.1.2 closes all three, and patching just got urgent.
- Author: Nicholas Robert
- Tags: Vulnerabilities, WordPress, Active Exploitation

WordPress patched three separate critical vulnerabilities in its core software inside a single week, and one of them was already under attack. The most serious, [CVE-2026-87902](https://www.cve.org/CVERecord?id=CVE-2026-87902&ref=thecybersignal.com), carries a CVSS score of 9.2 and was exploited within hours of its public disclosure, according to reporting from [The Hacker News](https://thehackernews.com/2026/09/attackers-exploit-wordpress-cve-2026.html?ref=thecybersignal.com) and [SecurityWeek](https://www.securityweek.com/critical-wordpress-vulnerability-exploited-immediately-after-disclosure/?ref=thecybersignal.com). The other two, nicknamed Comment2Shell and Click2Shell, were fixed before any public exploitation surfaced. The fully patched release is WordPress 7.1.2, and for defenders the takeaway across all three is the same: update now, then verify.

What makes this week notable is not a novel exploitation technique. It is the speed. A core WordPress flaw went from disclosure to real-world exploitation in hours, which collapses the comfortable gap site owners often assume sits between a patch landing and attackers acting on it. WordPress runs a large share of the web, so a core bug is not a niche plugin problem confined to one add-on. It is a single defect reachable across a very large population of sites, many of them run by people who are not full-time security staff.

Here is how the three flaws compare, and where each one stands.

| ● Three WordPress Core Flaws · September 2026 One week, three critical bugs, one of them exploited within hours. All three are closed in WordPress 7.1.2. |                                                                                                        |                                                                  |
| --------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------ | ---------------------------------------------------------------- |
| Flaw                                                                                                                                                      | What It Does                                                                                           | Where It Stands                                                  |
| CVE-2026-87902                                                                                                                                            | Unauthenticated remote code execution via a path-traversal flaw in page-template resolution.           | CVSS 9.2\. Exploited within hours of disclosure. Fixed in 7.1.2. |
| Comment2Shell (CVE-2026-93485)                                                                                                                            | A hidden script in an anonymous comment runs code on the server when an admin opens the page.          | Fixed September 17 in 7.1.1\. No public exploitation reported.   |
| Click2Shell                                                                                                                                               | A crafted link opened by a logged-in admin silently installs a theme from the WordPress.org directory. | Theme-install on its own. Can chain toward RCE. Fixed in 7.1.2.  |
| Source: The Hacker News and SecurityWeek reporting, September 2026\. Table: The CyberSignal.                                                              |                                                                                                        |                                                                  |

Summary of the three WordPress core flaws patched in September 2026, showing what each does and its current status. The exploited flaw, CVE-2026-87902, is marked in red. Source: The Hacker News and SecurityWeek, September 2026\. The CyberSignal.

## The CVE-2026-87902 Rapid Exploitation

CVE-2026-87902 is the one defenders should treat as an emergency. It is an unauthenticated remote code execution flaw, which means an attacker needs no login, no account, and no elevated role to reach it. It carries a CVSS score of 9.2, and, per [The Hacker News](https://thehackernews.com/2026/09/attackers-exploit-wordpress-cve-2026.html?ref=thecybersignal.com) and [SecurityWeek](https://www.securityweek.com/critical-wordpress-vulnerability-exploited-immediately-after-disclosure/?ref=thecybersignal.com), it was being exploited within hours of the details going public.

The root cause is a path-traversal weakness in how WordPress resolves page templates. The flaw sits in the `get_page_template()` function, the part of WordPress that decides which PHP template file to load when it renders a page. Because that resolution can be steered by an unauthenticated request, WordPress can be made to load a chosen readable local .php file instead of the intended template. Loading an attacker-selected local PHP file inside WordPress's own execution context is what turns a template-resolution bug into code running on the server. That is the whole distance from "wrong file picked" to "remote code execution," and it is why the CVSS score lands at 9.2.

The number is not the story, though. The timeline is. Most critical WordPress advisories give defenders at least a short grace period, the stretch of days or weeks between a fix shipping and functional exploit code circulating. CVE-2026-87902 did not offer that. The gap between "a patch exists" and "someone is using the bug" was measured in hours. For a site owner who batches updates for a weekly maintenance window, that model just failed: the window between disclosure and exploitation was shorter than the window between most people's update cycles.

**My read (assessment, not reported fact):** the 9.2 rating is almost beside the point. The combination that actually matters is unauthenticated, plus core, plus exploited-in-hours. Any one of those is serious. Together they mean this is a patch-tonight item, not a fix-it-this-sprint item, and any site that was internet-facing and unpatched during the exposure window should be treated as potentially reached, not presumed clean.

This is also not the first time in recent months that a WordPress remote code execution issue has moved from advisory to active exploitation faster than defenders would like. The same shape showed up with the [Elementor Pro unauthenticated upload flaw](https://www.thecybersignal.com/elementor-pro-cve-2026-32475-unauth-rce-2026/) and with the [miniOrange SAML SSO flaws that let attackers log in as any admin](https://www.thecybersignal.com/miniorange-saml-wordpress-cve-2026-61979-15981-2026/). The difference this time is that the bug is in WordPress core itself, not a single plugin, so the affected population is far wider.

## The Comment2Shell (CVE-2026-93485) Admin-Session Chain

Comment2Shell, tracked as CVE-2026-93485, is a quieter flaw that leans on an administrator's own session rather than a direct unauthenticated hit. Per [The Hacker News](https://thehackernews.com/2026/09/wordpress-comment2shell-flaw-can-turn.html?ref=thecybersignal.com), an anonymous visitor can plant a hidden script inside a comment. The comment sits there, dormant, until an administrator later opens the page that displays it. At that moment the script runs in the admin's context and can execute code on the server.

The detail defenders should hold onto is that no attacker credentials are involved anywhere in that sequence. The attacker never logs in. They rely entirely on a legitimate administrator opening a page, which is an ordinary, expected action. That is what makes stored-comment issues like this one dangerous out of proportion to how mundane they look: the privileged action that completes the chain is something the admin does every day without a second thought.

Comment2Shell was fixed on September 17 in WordPress 7.1.1, ahead of the 7.1.2 release that consolidates the week's fixes. If you moved to 7.1.1 when it shipped, you already have the Comment2Shell fix; 7.1.2 is still the release to land, because it also closes CVE-2026-87902 and Click2Shell. For sites that ran a vulnerable version with open or lightly moderated comments, the practical follow-up is to review comment content submitted before the patch, not just to install the update and move on.

## The Click2Shell No-Click Theme Install

Click2Shell, reported by researchers at [pwn.ai](https://thehackernews.com/2026/09/new-wordpress-click2shell-flaw-forces.html?ref=thecybersignal.com) and covered by The Hacker News, is the most conditional of the three, and worth describing precisely so the risk is neither overstated nor waved off. A crafted web link, opened by a logged-in administrator, causes WordPress to install a theme from the official WordPress.org directory without the admin ever clicking the Install button. The privileged action happens on the admin's behalf, triggered by nothing more than visiting a link while signed in.

On its own, the flaw only installs a theme. That is not remote code execution by itself, and it is important to say so rather than inflate it. The concern is chaining. A silent theme install is a foothold, and a foothold that can be combined with other weaknesses, a vulnerable theme, a second bug, a follow-on step, is how a "just a theme install" issue becomes a path to code execution. Treating it as harmless because the first step is limited would be the wrong lesson.

**Assessment:** Click2Shell is the lowest-urgency of the three in isolation and the one most dependent on attacker effort and admin behavior. But it belongs in the same patch action as the other two, because the fix ships together in 7.1.2 and because "only a theme install" is exactly the kind of primitive that gets stitched into a larger chain later.

## What WordPress Site Owners and Pros Should Verify (7.1.2)

Update every WordPress install to 7.1.2 immediately. That single step closes all three flaws. Then work the verification list below, because CVE-2026-87902 was exploited in the wild, and patching does not undo a compromise that already happened. A patch stops future exploitation; it does not evict an attacker who already got in.

- **Update to WordPress 7.1.2.** Confirm the version after updating rather than assuming an auto-update completed. This release is the one that carries all three fixes together.
- **Audit for CVE-2026-87902 exploitation.** Review web server and access logs for unexpected page-template loads and requests that resolve to unusual local .php files. On sites that were internet-facing and unpatched during the exposure window, treat anomalous template-resolution activity as worth investigating, not dismissing.
- **Review theme-install activity.** Check the installed-themes list and the themes directory for anything you did not add, which is the signal tied to Click2Shell. An unexplained theme appearing on a site that ran a vulnerable version deserves a closer look.
- **Review comment activity.** For Comment2Shell, examine comments submitted before the patch, especially any that an administrator may have opened in the admin view. Tighten comment moderation so unapproved comments are not rendered where a privileged user will trip over them.
- **Sweep for the aftermath.** Look for unknown administrator accounts, unexpected scheduled tasks, and web shells, and review logs for signs of post-exploitation activity. These checks matter most for CVE-2026-87902, given it was actively exploited.

If you are the person who has to decide which of these to fix first across dozens or hundreds of sites, that is a prioritization problem more than a technical one, and it is worth wiring into a real [vulnerability management](https://www.thecybersignal.com/vulnerability-management-the-complete-guide/) process rather than treating each advisory as a separate fire drill. The sites that got hurt this week were not the ones without a patch available. They were the ones whose update cadence was slower than the exploitation cadence.

## Open Questions

Several things are not confirmed as of publication, and it is more useful to state them plainly than to fill the gaps with guesses.

- **Named victims.** No specific victim sites have been publicly named in connection with the CVE-2026-87902 exploitation. That reporting could still emerge.
- **Threat actor.** No named group has been tied to the activity. Whether this is opportunistic mass scanning or a more targeted effort is not established in the public reporting.
- **Scale.** The number of sites actually exploited is not known. "Exploited within hours" describes the speed of the first activity, not the size of it, and the two should not be conflated.

What is not in question is the defender action. Three critical flaws in WordPress core, one of them already exploited, are all closed in WordPress 7.1.2\. The only variable left is how fast each site gets there.

## Primary Documents

- [The Hacker News: Attackers Exploit WordPress CVE-2026-87902](https://thehackernews.com/2026/09/attackers-exploit-wordpress-cve-2026.html?ref=thecybersignal.com)
- [SecurityWeek: Critical WordPress Vulnerability Exploited Immediately After Disclosure](https://www.securityweek.com/critical-wordpress-vulnerability-exploited-immediately-after-disclosure/?ref=thecybersignal.com)
- [The Hacker News: WordPress Issues Patch for Critical Vulnerability (7.1.2)](https://thehackernews.com/2026/09/wordpress-issues-patch-for-critical.html?ref=thecybersignal.com)
- [The Hacker News: WordPress Comment2Shell Flaw](https://thehackernews.com/2026/09/wordpress-comment2shell-flaw-can-turn.html?ref=thecybersignal.com)
- [The Hacker News: New WordPress Click2Shell Flaw](https://thehackernews.com/2026/09/new-wordpress-click2shell-flaw-forces.html?ref=thecybersignal.com)