WordPress 7.1.2 Patched as Attackers Escalate Exploitation of Critical Path Traversal Flaw

Attackers began exploiting a critical WordPress vulnerability within hours of its disclosure, escalating from reconnaissance to active remote code execution attempts. The flaw, CVE-2026-87902, allows unauthenticated attackers to load arbitrary PHP files if specific theme and server conditions are met. WordPress released version 7.1.2 to fix the issue, urging immediate updates as exploitation attempts surged tenfold.
Key points
- CVE-2026-87902 is a critical path traversal vulnerability with a CVSS score of 9.2, allowing unauthenticated remote code execution.
- Exploitation requires the active theme to have a top-level directory starting with 'page-' and a readable local PHP file on the server.
- Attackers escalated from reconnaissance to writing malicious files like 'pearcmd.php' to disk within hours of the patch release.
- WordPress released version 7.1.2 and backported fixes to all supported branches down to version 4.7.
- Patchstack reported that exploitation traffic increased tenfold and reached a wider spread of sites by September 24.
Background
This incident follows a pattern of rapid exploitation of critical web platform vulnerabilities, similar to the SharePoint RCE flaw CVE-2026-45659 exploited by ransomware groups in August 2026. It also mirrors the quick patching of the Chrome zero-day CVE-2026-87491 in September 2026, where attackers exploited the flaw before widespread updates could be deployed.
How outlets are covering it
The Hacker News and Help Net Security emphasize the technical preconditions for exploitation, noting that while the vulnerability is critical, specific server and theme configurations limit widespread compromise. SecurityWeek highlights a separate 'Click2Shell' vulnerability patched in version 7.1.1, which also allowed remote code execution via theme preview manipulation. Patchstack, cited by The Hacker News and Help Net Security, provides telemetry data showing a tenfold increase in exploitation attempts and a broader geographic spread of attacks, including IPs from the US and Indonesia. TechRadar offers general advice to update but lacks specific technical details compared to the other sources.
Why it matters
The rapid exploitation of CVE-2026-87902 underscores the risk of unpatched web platforms, even when exploitation requires specific preconditions. The tenfold increase in attack volume and the involvement of multiple security firms in tracking the activity highlight the urgency for website administrators to apply patches immediately to prevent potential remote code execution and data breaches.
What to watch
Website administrators are advised to update to WordPress version 7.1.2 or the latest patched versions for older branches (7.0.6, 6.9.9, 6.8.10) as soon as possible. They should also audit their sites for signs of malicious activity, such as unexpected PHP files in /tmp or /var/tmp directories. Security firms like Patchstack and Previdian will likely continue to monitor and report on exploitation attempts, while WordPress may issue further advisories if new vulnerabilities are discovered.
- Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure The Hacker News
- WordPress Patches ‘Click2Shell’ Vulnerability SecurityWeek
- WordPress 7.1.2 fixes critical unauthenticated path traversal vulnerability (CVE-2026-87902) Help Net Security
- Hackers are targeting a critical WordPress flaw, so be on your guard TechRadar
- WordPress Core Patched in Hours. Attackers Were Already Inside. forkast.news
Want the full story? Read the original reporting
Read on The Hacker News