HomeSecurityCritical WordPress vulnerability being exploited

Critical WordPress vulnerability being exploited

Just hours after a critical WordPress vulnerability, cybercriminals have begun actively exploiting it. Cybersecurity firm Patchstack first detected probing against websites and then activity that escalated into actual breach attempts.

Article Image: Critical WordPress Vulnerability Exploited Immediately After Disclosure

At the center of the issue is CVE-2026-87902 , a path traversal vulnerability in WordPress' page-template resolution . The flaw has a CVSS score of 9.2 , does not require prior authentication of the attacker, and, under certain circumstances, can lead from local file inclusion to remote code execution (RCE) .

How the WordPress vulnerability works

The issue is in the way WordPress handles page template names when creating a page. According to the official security update, an unauthenticated user could, under certain conditions, cause the import of a selected readable local PHP filethat is outside the allowed directories of the active theme.

This does not mean that every WordPress installation can automatically be compromised in the same way. For an attack to reach RCE, certain conditions must be combined in the active theme and the server environment.

See also: CVE-2026-63030: critical WordPress vulnerability in CISA KEV as actively exploited

Among other things, the active parent or child theme must have a top-level directory whose name begins with "page-". At the same time, the account under which the web server is running must be able to read an appropriate local PHP file.

The dangerous scenario with pearcmd.php

One of the elements that increases the severity of the vulnerability is its ability to be combined with pearcmd.php, a PEAR tool for managing PHP packages.

In certain configurations, this file can be used as an intermediate step to achieve RCE, especially when the register_argc_argv is enabled. Patchstack notes that the scenario concerns, among other things, the official PHP Docker image and default cPanel configurations with PHP before 8.5.

Requiring multiple prerequisites limits the set of systems that are in the worst-case scenario, but does not reduce the need to immediately install the available update.

The attacks began almost immediately

The speed with which the vulnerability was exploited is one of the most concerning aspects of the case. Patchstack recorded the first probing attempts on September 22, 2026, at 17:44 UTC, less than five hours after the release of WordPress 7.1.2.

See also: FireBox RCE: Critical vulnerability in WordPress WooCommerce plugin

Critical WordPress vulnerability being exploited

The company notes that the payloads corresponded to coding directly related to the patch, indicating that the attackers likely analyzed the patch diff to quickly understand the mechanism of the vulnerability.

Initially, the recorded attempts were reconnaissance. However, the activity then escalated. According to Patchstack, the traffic increased significantly and the attackers moved from identifying vulnerable installations to attempts to exploit the vulnerability.

Three stages in the attack

The activity that has been observed follows a relatively clear sequence. First, the attackers check if a WordPress site presents the characteristics required for the exploit.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Next, they look for the presence of the pearcmd.php . If the environment is suitable, the final stage can exploit the file to write malicious PHP content and ultimately execute code on the server. Patchstack continues to monitor whether activity will move from probes to more and more aggressive payloads.

Who should inform immediately?

WordPress addressed the issue with version 7.1.2, which was released on September 22 as a security release. The fix has also been ported to supported older branches, including versions 7.0.6, 6.9.9, 6.8.10, and 4.7.37, along with their respective interim releases.

The official WordPress recommendation is to install the available update immediately.

See also: WordPress: Critical vulnerability in Elementor Pro is used in cyberattacks

Particular attention is needed from administrators who maintain old installations, custom themes, or servers with PHP settings that may create the conditions for the most serious form of attack.

Critical WordPress vulnerability being exploited

For those who can't update immediately, monitoring web server logs for suspicious requests and checking for unknown or modified files can help identify possible prior activity. Patchstack also says it has mitigation rules to block related attacks.

The incident is yet another prime example of how quickly a publicly disclosed WordPress vulnerability into a practical attack tool. When a vulnerability affects the core of WordPress and does not require authentication, the speed of patch installation becomes a critical factor in protecting a website.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS