Race Against the Patch: Critical WordPress RCE Exploited Within Hours
CVE-2026-87902, a CVSS 9.2 unauthenticated PHP file inclusion flaw in WordPress core 4.7.0 to 7.1.1, was reverse-engineered from the 7.1.2 patch and exploited the same day to write malicious PHP onto vulnerable servers.
TA2026283Published September 25, 2026Admiralty A1TA2026283A1CVE-2026-879029.2CWE-98Summary
CVE-2026-87902 is a critical, unauthenticated flaw in WordPress core, rated CVSS 9.2 (CWE-98, PHP file inclusion). By sending a specially encoded path in a page request, an attacker can trick the get_page_template() function into loading a PHP file from outside the theme folder, and where the server and active theme meet a few common conditions, that becomes full remote code execution with no login required. It affects a wide range of WordPress versions, from 4.7.0 to 7.1.1.
There is no named group behind CVE-2026-87902: attackers reverse-engineered the fix as soon as WordPress shipped version 7.1.2 and started scanning the same day, quickly moving from simple checks to writing malicious PHP onto vulnerable servers. With a public exploit tool already circulating, any WordPress site that meets the preconditions should be treated as at risk of full compromise.
Affected Products
CVE
| CVE | Name | Affected Product | Zero-Day | CISA KEV | Patch |
|---|---|---|---|---|---|
CVE-2026-87902 | WordPress Unauthenticated Path Traversal Vulnerability | WordPress WordPress Core | No | No | Available |
Vulnerability Details
- #01
At its core,
CVE-2026-87902is a PHP file inclusion flaw (CWE-98) hiding inside WordPress's page-template logic. Attackers wasted no time with it: within hours of WordPress going public with the vulnerability, live sites were already being probed and hit. When WordPress builds a page,get_page_template()decides which template file to load based on the page's slug. WordPress runs that slug through its own sanitiser first, and that sanitiser was written to preserve percent-encoded characters while stripping literal dots and slashes. That gap is the whole problem, path is blocked, but a percent-encoded version survives the sanitiser and is then decoded, letting the template path climb out of the theme directory and point at any readable.phpfile on the server. - #02
To pull this off, an attacker sends a request that pairs a valid
page_idwith a craftedpagenamevalue. Thepage_idmatters, because without a real page WordPress returns a 404 and the vulnerable code never runs, which is also why the two parameters appearing together is such a useful detection signal. Thepagenamevalue usually begins with a real directory starting withpage-(such aspage-templates), then uses the encoded traversal to reach a target file. The favourite target is PHP'spearcmd.php. - #03
When the server has
register_argc_argvenabled, the query string is handed to the included script as command-line arguments. An attacker first sends+config-showto confirm the trick works, then switches to+config-createto write a file of their choosing, arbitrary PHP with attacker-controlled content, which is code execution. Observed activity drops these files into/tmpand/var/tmp; some are harmless proof-of-concept markers, while others plant a tag that runs a shell command or pulls in a web shell. - #04
The vulnerability affects WordPress core versions
4.7.0through7.1.1, an unusually long range that reaches back years. The "attack requirements present" element reflects the two preconditions: the active theme must have a top-level directory whose name starts withpage-, and a suitable readable.phptarget (such aspearcmd.php) must exist on the server. This is not theoretical, the first exploitation attempts hit sensors at11:49 UTCon22 September 2026, the very day the patch shipped, showing the payloads were built straight from the patch diff. By that afternoon the activity had moved from probing to writing files to disk, and by23 Septembera named Nuclei template was circulating and traffic had spiked, with independent honeypot telemetry recording dozens of attempts inside the first day.
Vulnerability
| CVE ID | Affected Products | Affected CPE | CWE ID |
|---|---|---|---|
CVE-2026-87902 | WordPress WordPress Core (4.7.0 – 7.1.1) | cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* | CWE-98 |
Recommendations
- 01Update WordPress Immediately
Apply WordPress
7.1.2right away, or the patched release for your branch,7.0.6,6.9.9,6.8.10, and backports reaching all the way to4.7.37. This is the only complete fix forCVE-2026-87902, and with active exploitation under way it should be treated as urgent rather than as routine maintenance. - 02Hunt for Signs of Compromise
Check
/tmpand/var/tmpfor unexpected.phpfiles, including names likewp-pear-rce-flag.php,poc87902.php, and files beginning withluci_orzeta_. Search web logs for apagenamevalue containing%2e%2eor%252e%252e, apagenamebeginning withtemplates%2f,pagenameandpage_idappearing together, or any request mentioningpearcmd,+config-show, or+config-create. If a normal page URL ever returned OPML or RSS content, treat that host as successfully probed and investigate it as potentially compromised. - 03Apply Temporary Mitigations If You Cannot Patch Yet
If an immediate update is not possible, block requests where the
pagenameparameter contains traversal sequences; a genuine page slug never does, so this can be filtered without affecting normal traffic. Disabling PHP'sregister_argc_argvsetting does not fix the inclusion itself, but it breaks the pearcmd chain, downgrading potential code execution to a lower-impact information leak. - 04Harden the PHP Environment
Remove or restrict PEAR and
pearcmd.phpon production web servers where they are not needed, since they are the primary springboard from file inclusion to full code execution. Run the web server under a least-privilege account so that even a successful inclusion has limited reach. - 05Vulnerability Management
Maintain an accurate inventory of your WordPress installations and their versions, keep automatic updates enabled, and place a virtual patching or web application firewall layer in front of internet-facing sites so newly disclosed flaws can be blocked quickly while patches roll out. Review the security posture of third-party themes and plugins regularly as part of this process.
Indicators of Compromise (IoCs)
| Type | Value |
|---|---|
IPv4 | 43[.]250[.]53[.]42 |
Filename | wp-pear-rce-flag.php |
File Path | /usr/local/lib/php/pearcmd.php |
MITRE ATT&CK TTPs
T1595T1595.002T1190T1059T1588T1588.006References & Patch Links
Patch Link
- WordPress Releases
https://wordpress.org/download/releases/
