Skip to content

Critical WordPress Vulnerability Under Active Exploitation

WordPress has released a critical security patch for a high-severity vulnerability (CVE-2026-87902) enabling unauthenticated path traversal and potential remote code execution (RCE). Exploitation attempts began within hours of the fix and have since escalated, targeting vulnerable sites globally.

By

Editor, LazyFounders

Published 5 min read
Critical WordPress Vulnerability Under Active Exploitation
Image: (Image credit: Shutterstock) via source

WordPress has released a critical security patch for a high-severity vulnerability (CVE-2026-87902) enabling unauthenticated path traversal and potential remote code execution (RCE). Exploitation attempts began within hours of the fix and have since escalated, targeting vulnerable sites globally.

30 SEC SUMMARY

  • WordPress has patched a critical vulnerability (CVE-2026-87902) rated 8.1 in severity, enabling unauthenticated path traversal and potential remote code execution (RCE).
  • The flaw affects WordPress Core and can be exploited to include local PHP files outside active theme directories, with RCE risk in specific configurations.
  • Exploitation attempts began within hours of the patch’s release and have since escalated, targeting vulnerable sites globally.
  • WordPress version 7.1.2 and backported fixes for versions 4.7+ address the issue, while older versions remain unpatched.
  • Interim mitigations include blocking traversal sequences and disabling register_argc_argv in PHP settings.

TABLE OF CONTENTS

  • Critical Vulnerability in WordPress Core
  • Patch Release and Exploitation Timeline
  • Affected Systems and Mitigations
  • Why This Vulnerability Matters
  • What this means
  • Key takeaways
  • FAQ
  • Sources

KEY HIGHLIGHTS

  • CVE-2026-87902 is a high-severity (8.1) path traversal vulnerability in WordPress Core, enabling unauthenticated attackers to include local PHP files.
  • Remote code execution (RCE) is possible on sites with specific configurations, such as parent/child themes using ‘page-’ directories.
  • The vulnerability was patched in WordPress 7.1.2 and backported to versions 4.7+, while versions before 4.8 remain unsupported.
  • Exploitation attempts began within five hours of the patch’s release and have since escalated globally.
  • Attackers are leveraging the flaw to write malicious PHP files via pearcmd.php.

Critical Vulnerability in WordPress Core

According to TechRadar, a critical vulnerability in WordPress Core, tracked as CVE-2026-87902, enables unauthenticated path traversal and potential remote code execution (RCE). The flaw is rated 8.1 out of 10 in severity, classifying it as a high-risk issue.

The vulnerability allows attackers to include local PHP files outside the active theme directories. In specific configurations—such as sites using parent or child themes with top-level directories starting with ‘page-’—this can escalate to RCE. WordPress powers over 50% of active websites, amplifying the potential impact.

Patch Release and Exploitation Timeline

WordPress addressed the vulnerability in version 7.1.2, with backported fixes for versions 4.7 and above. Sites running versions before 4.8, which are no longer supported, will not receive a patch and remain vulnerable.

Exploitation attempts began roughly five hours after the patch’s release, according to TechRadar. Initial activity was primarily reconnaissance, but malicious attacks surged tenfold in the hours that followed. Attackers are now using the flaw to include pearcmd.php and write malicious PHP files to disk.

Public scanning tools for CVE-2026-87902 are already in circulation, increasing the risk of widespread attacks.

Affected Systems and Mitigations

Beyond WordPress Core, the vulnerability also impacts the official PHP image for Docker and default cPanel configurations if running PHP versions before 8.5.

TechRadar reports that admins can reduce risk by blocking traversal sequences in the pagename parameter. Disabling register_argc_argv in PHP settings breaks the pearcmd attack chain, limiting exposure to an information leak rather than full RCE.

Why This Vulnerability Matters

WordPress’s dominance as a content management system (CMS) makes its vulnerabilities a prime target for attackers. With over half of all active websites relying on WordPress, even narrowly scoped flaws can have outsized consequences if exploited at scale.

Recent trends in cybersecurity, such as the rise of AI-driven attack tools and phishing-as-a-service platforms, highlight the urgency of patch management. Microsoft’s recent disruption of the EvilTokens phishing platform underscores how quickly threats can evolve and scale.

What this means

LazyFounders analysis — our interpretation, not reported fact.

This vulnerability is a stark reminder of how quickly high-severity flaws can turn into active threats. For founders and operators running WordPress sites, the timeline here is critical: exploitation began within hours of the patch’s release, leaving no room for delay.

The specificity of the RCE risk—limited to sites with certain theme configurations—might tempt some to assume they’re safe. That would be a mistake. Path traversal alone can expose sensitive files, and attackers are already adapting their methods, as seen with the pearcmd.php attacks.

For startups, this is also a lesson in technical debt. Unsupported WordPress versions (pre-4.8) are now liabilities, and the backported fixes only go so far. If your stack includes older versions or misconfigured themes, the cost of upgrading will only rise as attacks intensify.

The mitigations here—blocking traversal sequences and disabling register_argc_argv—are stopgaps, not solutions. They buy time, but patching is the only sustainable fix. If you’re running WordPress at scale, automate updates where possible and prioritize visibility into your theme configurations.

Key takeaways

  • A high-severity vulnerability (CVE-2026-87902) in WordPress Core allows unauthenticated path traversal and potential RCE.
  • Only sites with specific configurations (e.g., parent/child themes with ‘page-’ directories) are at risk of RCE.
  • The flaw was patched in WordPress 7.1.2 and backported to versions 4.7+, but older versions are unsupported and vulnerable.
  • Exploitation attempts surged within hours of the patch’s release, with attackers now writing malicious PHP files to disk.
  • Immediate updates or mitigations—such as blocking traversal sequences or disabling register_argc_argv—are critical to reducing risk.

FAQ

What is CVE-2026-87902?

CVE-2026-87902 is a high-severity vulnerability in WordPress Core that allows unauthenticated attackers to perform path traversal. In certain configurations, this can lead to remote code execution (RCE). The flaw is rated 8.1 out of 10 in severity.

Which WordPress versions are affected?

The vulnerability affects WordPress Core versions before 7.1.2. Patches have been backported to versions 4.7 and above. Versions before 4.8 are unsupported and will not receive a fix, leaving them vulnerable.

How quickly are attackers exploiting this flaw?

Exploitation attempts began within five hours of the patch’s release and have since become widespread. Attackers are actively using the vulnerability to write malicious PHP files to disk via pearcmd.php.

What configurations increase the risk of RCE?

Sites using parent or child themes with top-level directories starting with ‘page-’ are at higher risk of remote code execution. However, path traversal itself can expose sensitive files even without RCE.

What mitigations are available?

Admins can block traversal sequences in the pagename parameter and disable register_argc_argv in PHP settings. These measures reduce risk but do not replace the need to update to a patched version.

Related on LazyFounders

Sources

  1. TechRadar · 2026-09-24
    Hackers are targeting a critical WordPress flaw, so be on your guard

This story is an original summary drafted with AI by LazyFounders from the reporting listed above and checked by automated validation. Facts are attributed to their original publishers; sections marked as analysis are LazyFounders's. Where a source is in another language, facts were machine-translated and quotations are reported, not reproduced. Read the original coverage via the links, and see our AI policy and corrections policy.

Get the LazyFounder Brief

Startup, funding and AI news in a five-minute read. Join the early-access list.

Lazy Founder - Powered by Blogy.in