BleepingComputerThursday · September 24, 2026FREE

Hackers start exploiting critical WordPress flaw for code execution

wordpresssecurityexploitcode-execution

BleepingComputer reported on September 23, 2026, that hackers have started exploiting a critical WordPress flaw for code execution. According to the source, exploitation activity is already underway, and the vulnerability in question allows code execution. The report frames the flaw as critical and characterizes the activity as active exploitation rather than a theoretical risk. The available source text does not identify the specific WordPress component involved, the affected versions, the vulnerability identifier, the attackers behind the activity, or the number of sites impacted. It also does not describe how the exploitation works, what conditions are required, or whether a fix has been released. Because the excerpt is limited to the headline and publication metadata, the digest is restricted to what the source states: a critical WordPress flaw exists, it enables code execution, and hackers have begun exploiting it.

// why it matters

The source says a critical WordPress flaw enabling code execution is being actively exploited, which is relevant to developers running WordPress.

Sources

Primary · BleepingComputer
▸ Read original at bleepingcomputer.com

Like this? Get the next digest.

Hackers start exploiting critical WordPress flaw for code execution — aigest.dev