Hackers are actively exploiting CVE-2026-87902, a critical WordPress flaw that can lead to remote code execution. Here’s what admins should do.