Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: web-security (3 articles)Clear

Elementor WordPress plugin flaw lets one link create a rogue administrator account

Patchstack detailed a high-severity cross-site request forgery flaw, rated 8.8 and not yet assigned a CVE, in the Elementor Website Builder WordPress plugin, which is active on over ten million sites. It affects only versions 4.3.0 and 4.3.1, installed on more than two million sites, and is fixed in 4.3.2. One link opened by a logged-in WordPress user makes that user perform any REST API action their account permits, so an administrator clicking it creates a second administrator account for the attacker on a stock install. The attack needs no JavaScript, submitted form, or attacker-controlled page; the link can be a plain anchor tag in an email, chat, or comment.

Check
Update the Elementor plugin to 4.3.2 across all WordPress sites, then audit administrator accounts for unexpected additions created via the flaw.
Affected
Sites running Elementor 4.3.0 or 4.3.1 let an unauthenticated attacker trick a logged-in admin into creating a rogue administrator account by clicking a link.
Fix
Apply Elementor 4.3.2, remove unrecognized admin accounts, and warn administrators against opening untrusted links while signed in to WordPress.

Attackers exploit unauthenticated WordPress code execution flaw within hours of its disclosure

Threat actors began exploiting a critical WordPress flaw, CVE-2026-87902, rated 9.2, within hours of its public disclosure. The bug lets an unauthenticated attacker make get_page_template() include a chosen readable local .php file outside the active theme directories, which can lead to remote code execution when server and theme preconditions are met. Exploitation requires the active child or parent theme to contain a top-level directory whose name starts with page-, and a readable local .php target such as pearcmd.php. Previdian reported honeypot exploitation attempts from a New Jersey IP that include /usr/local/lib/php/pearcmd.php, write a file to /tmp, then pull a PHP upload script from GitHub to plant a web shell.

Check
Update WordPress to the patched release now, then check whether active themes contain page- prefixed directories and review web logs for pearcmd.php requests.
Affected
WordPress sites meeting the theme and server preconditions let an unauthenticated attacker chain local file inclusion into remote code execution, already seen in the wild.
Fix
Apply the WordPress patch, harden PHP to disable pearcmd.php inclusion, and block the observed exploit indicators at the web tier.

WordPress flaw forces theme installs and can chain to server code execution

WordPress shipped 7.1.1 on September 17 to fix a flaw that pwn.ai calls Click2Shell, where a crafted link opened by a logged-in administrator installs a theme from the official directory with no click. Two parts of WordPress read the link differently, so attacker-added characters steer the admin browser into clicking Install, and the logged-in session supplies the permission and security token. Alone it only installs a real, switched-off theme, but the researchers chained it with a second flaw in the Mobile Repair Zone theme, whose handler fetched and ran remote code during a Customizer preview, reaching server code execution. No in-the-wild abuse is reported.

Check
Update all WordPress sites to 7.1.1 immediately, then audit installed themes for unexpected additions and remove any that administrators did not intend.
Affected
Sites where an administrator opens a crafted link can silently install an attacker-chosen theme, which can chain with a vulnerable theme to code execution.
Fix
Apply 7.1.1, remove unused themes, and warn administrators against opening untrusted links while authenticated to the WordPress dashboard.