Skip to content
TECH CEO Daily
CybersecuritySecurity Alert

WordPress core vulnerability CVE-2026-87902 exploited hours after 7.1.2 patch

An unauthenticated file-inclusion bug in WordPress core can reach remote code execution on some servers. CISA added it to its exploited-flaws catalog on September 25.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1WordPress 7.1.2, released September 22, fixes CVE-2026-87902, rated 9.2 on CVSS v4 and exploitable without logging in.
  • 2Researchers logged exploit attempts within hours, and CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 25.
  • 3Code execution needs a “page-” theme folder, a usable PHP file such as PEAR's pearcmd.php and PHP's register_argc_argv setting, but every release from 4.7.0 through 7.1.1 is affected.

The news

A critical WordPress core vulnerability, CVE-2026-87902, came under attack within hours of the September 22 release of WordPress 7.1.2, researchers said. On September 25, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added it to its exploited-flaws catalog.

The bug sits in get_page_template(), the core function that decides which theme file renders a page. According to Patchstack, a WordPress security firm, the function did not run the pagename value taken from the URL through WordPress's validate_file() check, as similar code paths do. That gap lets an attacker with no account point WordPress at a readable PHP file outside the active theme's folders, a class of bug known as local file inclusion.

WordPress rated the issue critical and said the fix was backported to every branch still eligible for security updates, going back to version 4.7. Patchstack and Help Net Security put the CVSS v4 severity score at 9.2 and the affected range at 4.7.0 through 7.1.1. Sites with automatic background updates switched on should receive the fix without any action. The project credited researcher Robert Ressl with reporting the flaw.

Turning file inclusion into remote code execution, meaning the ability to run an attacker's own code on the server, takes extra conditions. Patchstack said the active theme must contain a top-level folder whose name starts with “page-”, and the server must hold a readable PHP file that is useful to an attacker when included. The best-known candidate is PEAR's pearcmd.php, which works only when PHP's register_argc_argv setting is enabled. Patchstack noted that setting is on by default in official PHP Docker images and in cPanel environments running PHP below 8.5. The Hacker News reported that attackers were including pearcmd.php and using it to write malicious PHP files to disk, as did Patchstack in an update quoted by Help Net Security.

The Hacker News reported that the first exploitation was recorded at 11:49 a.m. UTC on September 22, and that security firm Previdian logged 68 attempts starting September 23. Patchstack also said traffic against the flaw was running at more than ten times its first-evening level. According to Patchstack, as quoted by SecurityWeek, the attack payloads targeted the precise encoding the patch fixes, indicating they were built from the code changes rather than discovered independently. SecurityWeek also listed older default themes such as Twenty Twelve and Twenty Fourteen, plus third-party themes Neve, Hestia and Sydney, among those with qualifying folders.

The numbers

CVSS v4 severity score
9.2
Affected WordPress versions
4.7.0 through 7.1.1
Fixed release
WordPress 7.1.2 (September 22, 2026)
Exploit attempts logged by Previdian from September 23
68
Date added to CISA KEV catalog
September 25, 2026

Why CEOs should care

For CISOs and IT leaders, the priority is inventory. Many companies run WordPress well beyond the main website: campaign microsites, regional pages, investor-relations portals and agency-built properties that no central team patches. Ask marketing and web teams for a list of every WordPress instance, its version and whether automatic background updates are enabled. Anything below 7.1.2, or below the matching backport such as 7.0.6, 6.9.9 or 6.8.10, should be treated as exposed.

Where patching lags, security teams can narrow the risk while they update. Patchstack advises checking whether the active theme has folders beginning with “page-” and whether register_argc_argv is enabled in PHP. Because exploitation started on disclosure day, sites that stayed unpatched after September 22 should also be checked for unfamiliar PHP files in temporary directories. The Hacker News reported file names such as poc87902.php and wp-pear-rce-flag.php in observed attacks.

For CFOs and boards, the lesson is about exposure windows. A single core flaw spanning nearly a decade of releases turned into live attacks within hours. Contracts with web agencies and hosting providers should set patch timelines for critical core updates, and managed hosts should be asked to confirm in writing that they applied 7.1.2 or the relevant backport.

The bigger picture

The WordPress case shows how quickly a published fix can double as a guide for attackers, with the first recorded exploitation coming on the same day the patch shipped. CISA's alert said flaws of this kind are commonly used by hackers and put federal networks at serious risk. Its Binding Operational Directive 26-04 tells federal civilian agencies to prioritize fixes for catalog entries, especially on internet-facing systems, and the agency urges private organizations to follow the same risk-based approach.

Help Net Security reported that the fix shipped across 25 versions, a sign of how much legacy WordPress code remains in circulation. WordPress itself notes that only its most recent release receives active support, which leaves organizations on older branches dependent on backports.

What’s next

Watch for further indicators of compromise from Patchstack and hosting providers, and for attack chains that go beyond the pearcmd.php technique. Organizations should confirm patch status across all WordPress properties, review web server logs from September 22 onward, and check whether theme vendors whose products ship with “page-” folders issue their own guidance.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

WordPressCISAPatchstackVulnerabilities

Earlier coverage of WordPress

All WordPress coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.