Hackers start exploiting critical WordPress flaw for code execution
BleepingComputer reports that hackers have started exploiting a critical WordPress flaw to achieve code execution. The source, published September 23, 2026, states that exploitation of the vulnerability is underway and that the flaw enables code execution. No further details about the vulnerability, the attackers, the affected versions, or the number of impacted sites are provided in the available source text.
The source says a critical WordPress flaw enabling code execution is being actively exploited, which is relevant to developers running WordPress.

