WordPress 7.1.2 Patched as Attackers Escalate Exploitation of Critical Path Traversal Flaw

3 min read
Source: The Hacker News
WordPress 7.1.2 Patched as Attackers Escalate Exploitation of Critical Path Traversal Flaw
Photo: The Hacker News
TL;DR

Attackers began exploiting a critical WordPress vulnerability within hours of its disclosure, escalating from reconnaissance to active remote code execution attempts. The flaw, CVE-2026-87902, allows unauthenticated attackers to load arbitrary PHP files if specific theme and server conditions are met. WordPress released version 7.1.2 to fix the issue, urging immediate updates as exploitation attempts surged tenfold.

Key points

  • CVE-2026-87902 is a critical path traversal vulnerability with a CVSS score of 9.2, allowing unauthenticated remote code execution.
  • Exploitation requires the active theme to have a top-level directory starting with 'page-' and a readable local PHP file on the server.
  • Attackers escalated from reconnaissance to writing malicious files like 'pearcmd.php' to disk within hours of the patch release.
  • WordPress released version 7.1.2 and backported fixes to all supported branches down to version 4.7.
  • Patchstack reported that exploitation traffic increased tenfold and reached a wider spread of sites by September 24.

Background

This incident follows a pattern of rapid exploitation of critical web platform vulnerabilities, similar to the SharePoint RCE flaw CVE-2026-45659 exploited by ransomware groups in August 2026. It also mirrors the quick patching of the Chrome zero-day CVE-2026-87491 in September 2026, where attackers exploited the flaw before widespread updates could be deployed.

How outlets are covering it

The Hacker News and Help Net Security emphasize the technical preconditions for exploitation, noting that while the vulnerability is critical, specific server and theme configurations limit widespread compromise. SecurityWeek highlights a separate 'Click2Shell' vulnerability patched in version 7.1.1, which also allowed remote code execution via theme preview manipulation. Patchstack, cited by The Hacker News and Help Net Security, provides telemetry data showing a tenfold increase in exploitation attempts and a broader geographic spread of attacks, including IPs from the US and Indonesia. TechRadar offers general advice to update but lacks specific technical details compared to the other sources.

Why it matters

The rapid exploitation of CVE-2026-87902 underscores the risk of unpatched web platforms, even when exploitation requires specific preconditions. The tenfold increase in attack volume and the involvement of multiple security firms in tracking the activity highlight the urgency for website administrators to apply patches immediately to prevent potential remote code execution and data breaches.

What to watch

Website administrators are advised to update to WordPress version 7.1.2 or the latest patched versions for older branches (7.0.6, 6.9.9, 6.8.10) as soon as possible. They should also audit their sites for signs of malicious activity, such as unexpected PHP files in /tmp or /var/tmp directories. Security firms like Patchstack and Previdian will likely continue to monitor and report on exploitation attempts, while WordPress may issue further advisories if new vulnerabilities are discovered.

Share this article

Want the full story? Read the original reporting

Read on The Hacker News