Build1 publisherNot yet confirmed elsewhere2 min readPublished
WordPress patches a no-login path-traversal bug that default server settings turn into RCE
WordPress shipped 7.1.2 on 22 September 2026 to patch CVE-2026-87902, an unauthenticated path-traversal flaw rated 9.2 that reaches every release since 4.7.0. CISA listed it as known-exploited three days later.
The Engineer · Build desk
What happened
- The flaw sits in page template resolution: an unauthenticated request can steer get_page_template() into including a readable local .php file from outside the active theme, which the advisory classes as the file-inclusion weakness CWE-98.
- WordPress backported the fix to every branch still eligible for security updates, from 7.0.6 down to 4.7.37, so a site held on an older major is not left without a patch.
- The disclosure reports public scanning tools already hunting for vulnerable installs, along with attempts in the wild to write PHP files through pearcmd.php.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- exposure Each of the three conditions is a default somewhere, so a conditional RCE here describes a common server, and the caveat gives site owners little real protection.
- constraint On shared hosting the risky PHP settings belong to the host, not the tenant, so for most site owners updating core is the only lever they control.
- decision Patching closes this bug only; the disclosure's second step, blocking PHP execution, is what limits what the next file-inclusion flaw can run.
Including a file is not the same as running attacker code in it, and that gap is what "conditional" means here. Three things have to line up. The active theme, parent or child, needs a top-level directory whose name starts with page-; that is not exotic, since page-templates/ ships in Twenty Twelve and Twenty Fourteen and in the Neve, Hestia and Sydney themes [12]. The server needs a readable .php file that acts on attacker-supplied arguments, which in practice means pearcmd.php [13]. And register_argc_argv has to be set to On, the default in official PHP Docker images and in cPanel on PHP before 8.5 [14].
The write-up tells owners to check their own install. Its two descriptions of the risk do not quite match. The opening warns that many shared hosting and default VPS setups are likely to qualify [17]. The detailed section is more careful, calling the conditions "narrower and far more specific than 'a misconfigured server'" [18].
On the current branch the patched build is 7.1.2 [7]. An install pinned to an older major is not stuck: the backports run 7.0.6, 6.9.9, 6.8.10, 6.7.9 and on down to 4.7.37 [15]. The disclosure recommends updating with wp core update over WP-CLI, then adding define( 'WP_AUTO_UPDATE_CORE', 'minor' ) to wp-config.php, so the next security release installs without a manual step [1].
What to watch
- Whether the pearcmd.php write attempts seen in the wild turn into confirmed, working RCE at scale.
- Whether managed and shared hosts push the 7.1.2 backport automatically or leave patching to individual tenants.
- An expanded advisory naming which other themes and plugins add a page- directory beyond those listed.