Hackers start exploiting critical WordPress flaw for code execution
CVE-2026-87902 is a critical unauthenticated path traversal vulnerability in WordPress that allows attackers to include arbitrary local PHP files outside the active theme directories. Under specific conditions, this can lead to remote code execution (RCE). The flaw was patched in WordPress 7.1.2 and backported to versions down to 4.7. Attackers have moved from reconnaissance to active exploitation, writing malicious PHP files to disk that execute shell commands when accessed.
AI Analysis
Technical Summary
CVE-2026-87902 is an unauthenticated path traversal vulnerability discovered in WordPress that enables attackers to exploit the get_page_template() function to include arbitrary readable local PHP files outside the active theme directories. For RCE to occur, the active theme must have a top-level directory starting with 'page-', the targeted PHP file must exist and be readable by the web server, and PHP’s register_argc_argv setting must be active. The vulnerability affects WordPress versions prior to 7.1.2, with fixes backported to versions as early as 4.7. Attackers have been observed escalating from reconnaissance to writing malicious PHP payloads to /tmp and /var/tmp directories, which execute shell commands upon access. The vulnerability also affects the official PHP Docker image and default cPanel configurations running PHP versions before 8.5. The WordPress security team assigned a critical severity score of 9.2. Patchstack researchers observed a tenfold increase in exploitation attempts shortly after the patch release.
Potential Impact
The vulnerability allows unauthenticated attackers to achieve remote code execution on vulnerable WordPress sites by including and executing arbitrary PHP files. This can lead to full site compromise, unauthorized file writes, and execution of shell commands. The exploitation is active in the wild, with attackers writing malicious PHP files to temporary directories to maintain persistence and control. The flaw also impacts related PHP environments such as the official PHP Docker image and cPanel configurations with PHP versions before 8.5, broadening the potential attack surface.
Mitigation Recommendations
WordPress has released version 7.1.2 which addresses CVE-2026-87902, with backported fixes to all supported branches down to version 4.7. Site administrators should update to WordPress 7.1.2 or later immediately. Versions prior to 4.7 are not patched and should be upgraded to a supported version. Additionally, reviewing server logs for signs of exploitation and blocking known malicious IP addresses (169.58.48.193, 169.58.48.195, 2001:df1:e8c0::106b) is recommended. No other mitigations are noted in the advisory. The vendor manages remediation for WordPress as a self-hosted platform; administrators must apply updates themselves.
Hackers start exploiting critical WordPress flaw for code execution
Description
CVE-2026-87902 is a critical unauthenticated path traversal vulnerability in WordPress that allows attackers to include arbitrary local PHP files outside the active theme directories. Under specific conditions, this can lead to remote code execution (RCE). The flaw was patched in WordPress 7.1.2 and backported to versions down to 4.7. Attackers have moved from reconnaissance to active exploitation, writing malicious PHP files to disk that execute shell commands when accessed.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-87902 is an unauthenticated path traversal vulnerability discovered in WordPress that enables attackers to exploit the get_page_template() function to include arbitrary readable local PHP files outside the active theme directories. For RCE to occur, the active theme must have a top-level directory starting with 'page-', the targeted PHP file must exist and be readable by the web server, and PHP’s register_argc_argv setting must be active. The vulnerability affects WordPress versions prior to 7.1.2, with fixes backported to versions as early as 4.7. Attackers have been observed escalating from reconnaissance to writing malicious PHP payloads to /tmp and /var/tmp directories, which execute shell commands upon access. The vulnerability also affects the official PHP Docker image and default cPanel configurations running PHP versions before 8.5. The WordPress security team assigned a critical severity score of 9.2. Patchstack researchers observed a tenfold increase in exploitation attempts shortly after the patch release.
Potential Impact
The vulnerability allows unauthenticated attackers to achieve remote code execution on vulnerable WordPress sites by including and executing arbitrary PHP files. This can lead to full site compromise, unauthorized file writes, and execution of shell commands. The exploitation is active in the wild, with attackers writing malicious PHP files to temporary directories to maintain persistence and control. The flaw also impacts related PHP environments such as the official PHP Docker image and cPanel configurations with PHP versions before 8.5, broadening the potential attack surface.
Mitigation Recommendations
WordPress has released version 7.1.2 which addresses CVE-2026-87902, with backported fixes to all supported branches down to version 4.7. Site administrators should update to WordPress 7.1.2 or later immediately. Versions prior to 4.7 are not patched and should be upgraded to a supported version. Additionally, reviewing server logs for signs of exploitation and blocking known malicious IP addresses (169.58.48.193, 169.58.48.195, 2001:df1:e8c0::106b) is recommended. No other mitigations are noted in the advisory. The vendor manages remediation for WordPress as a self-hosted platform; administrators must apply updates themselves.
Technical Details
- Classification
- {"confidence":0.76,"severitySource":"heuristic","classifier":"rss-v2"}
Threat ID: 6ab41ed6f7a7c541062f0b81
Added to database: 09/23/2026, 18:47:50 UTC
Last enriched: 09/23/2026, 18:48:01 UTC
Last updated: 09/24/2026, 03:34:29 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.