Security news

WordPress security news, weekly: what changed and what to do about it.

One briefing a week for the people who keep WordPress sites and the servers under them running. Each issue covers what is being exploited, what was patched, which versions close it, what to search your logs and file systems for, and a short list of actions in priority order. Core and plugins are covered alongside the hosting stack — cPanel and WHM, CloudLinux, PHP, Imunify — because that is where a site compromise turns into a server one.

Cadence
A new briefing every week
Covers
WordPress Core, plugins, and the hosting stack: cPanel/WHM, CloudLinux, PHP, Imunify
Sourcing
Every claim links to the advisory or research that published it
Author
G. Schad, WordPress and Linux security specialist

Weekly briefings

Every briefing so far, newest first

Weekly briefing · 5 October 2026

WordPress security this week: from patching to incident response

CVE-2026-87902 is now exploited through pearcmd.php, cPanel fixed a root flaw, and six plugins need urgent updates. What changed this week and what to do.

  • CVE-2026-87902
  • cPanel and WHM
  • Plugin fixes
Read this briefing

How each briefing is written

What a briefing covers, and how its claims are checked

Exploitation first

A flaw that is being used in real attacks comes before a flaw that is merely severe. Each item says which it is, and on what evidence.

Versions you can check

Every vulnerable range and fixed version is given exactly, so you can compare it against what is installed rather than guess from a headline.

Indicators, not just patches

Updating closes the door; it does not remove anyone already inside. Where a flaw has been exploited, the briefing lists what to search your logs and file systems for.

The server under the site

cPanel, WHM, CloudLinux, PHP and Imunify fixes are covered because a compromised hosting account is where a site incident becomes a server incident.

Sources named

Every claim links to the vendor advisory, database entry, or research that published it. Where sources disagree, or only one source exists, the briefing says so.

Nothing from client work

Briefings are compiled from published sources. Nothing in them is drawn from client incidents in a way that could identify anyone.