{
  "type": "bundle",
  "id": "bundle--b275e10d-12be-498d-808d-5d1c5ca4d4d5",
  "objects": [
    {
      "type": "report",
      "spec_version": "2.1",
      "id": "report--b04b21b9-74df-41d8-bd59-7c1fa41af6e9",
      "created": "2026-09-24T12:22:07.000Z",
      "modified": "2026-09-24T12:22:07.000Z",
      "name": "Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure",
      "description": "Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure. The vulnerability in question is CVE-2026-87902 (CVSS score: 9.2), which could allow an unauthenticated attacker to obtain remote code execution (RCE). \"An unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable local .php file",
      "published": "2026-09-24T05:36:18.000Z",
      "report_types": [
        "threat-report"
      ],
      "object_refs": [
        "vulnerability--4b1d88b7-a589-4d30-a1d6-9be3dad59a04",
        "attack-pattern--af05a666-e031-4f3a-b1ce-51d7c5af6932"
      ],
      "external_references": [
        {
          "source_name": "The Hacker News",
          "url": "https://thehackernews.com/2026/09/attackers-exploit-wordpress-cve-2026.html",
          "description": "Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure"
        }
      ],
      "labels": [
        "Media"
      ]
    },
    {
      "type": "vulnerability",
      "spec_version": "2.1",
      "id": "vulnerability--4b1d88b7-a589-4d30-a1d6-9be3dad59a04",
      "created": "2026-09-24T12:22:07.000Z",
      "modified": "2026-09-24T12:22:07.000Z",
      "name": "CVE-2026-87902",
      "external_references": [
        {
          "source_name": "cve",
          "external_id": "CVE-2026-87902",
          "url": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-87902"
        }
      ]
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--af05a666-e031-4f3a-b1ce-51d7c5af6932",
      "created": "2026-09-24T12:22:07.000Z",
      "modified": "2026-09-24T12:22:07.000Z",
      "name": "Command and Scripting Interpreter",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1059",
          "url": "https://attack.mitre.org/techniques/T1059/"
        }
      ],
      "kill_chain_phases": [
        {
          "kill_chain_name": "mitre-attack",
          "phase_name": "execution"
        }
      ]
    }
  ]
}