Skip to content

Build1 publisher2 min readPublished

Exploit attempts for WordPress CVE-2026-87902 began the day 7.1.2 shipped

WordPress released 7.1.2 on 22 September 2026 to fix remote file inclusion flaw CVE-2026-87902, and the first exploit attempt was recorded the same day. The fix was back-ported to every maintained branch down to 4.7, so an exposed site has hours before scanners find it.

The Engineer · Build desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Exploit attempts for WordPress CVE-2026-87902 began the day 7.1.2 shipped
Generated illustration

What happened

  • The flaw lets an unauthenticated attacker steer get_page_template() into including a readable PHP file from outside the active theme directory.
  • Exploitation needs two preconditions: a top-level theme directory whose name starts with page-, and a PHP file on the server that the web service account can read.
  • Security firm Previdian's honeypots logged 68 exploitation attempts, with early requests from a New Jersey address and later traffic from Indonesian ranges.
  • When the reachable file is pearcmd.php and PHP has register_argc_argv enabled, the inclusion becomes file writes to temporary directories and then code execution.
  • The patch ships as 7.1.2, 7.0.6, 6.9.9, 6.8.10, 6.7.9 and the back-ported 4.7.37.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • decision The open question for operators is how fast they can upgrade, because the evidence already shows the bug is exploited.
  • constraint Managed hosting, restrictive file permissions and a staging process each slow the one-click upgrade that closes the hole.
  • exposure The sites scanners will still find are those pinned to an old version, running a plugin that disabled auto-updates, or on a hosting panel with a stale PHP runtime.
  • capability Disabling register_argc_argv breaks the PEAR step of the chain and leaves the inclusion defect in place, so it lowers exposure without fixing the bug.

The first precondition is ordinary. The active parent or child theme has to contain a top-level folder whose name starts with page-, and the official Twenty Twelve and Twenty Fourteen families satisfy that on their own. [13] Template resolution code runs on the request path for every page view. [21]

The second precondition turns a file read into code execution. pearcmd.php, the file seen in the observed traffic, ships with the PEAR package manager on many Linux distributions. [6] In the recorded sessions, attackers probed with harmless core files first and only then reached for PEAR installation paths, the familiar reconnaissance-into-exploitation order. [9]

The honeypot figures describe one sensor network, not the whole internet. Attack attempts were observed within hours of the patch. [2] For that pace to apply to a given site, the site has to be reachable and advertising a detectable version. Most WordPress installs do exactly that. A scanner then needs only a host list and a request template. [11]

The stopgaps reduce exposure and little else. Blocking path traversal in the pagename parameter at the firewall is the first suggestion, but the reporting notes encodings varied widely and a single rule is unlikely to catch every variant. [14] Checking /tmp and /var/tmp for unfamiliar PHP files is incident response, not prevention; the named artifacts include wp-pear-rce-flag.php, poc87902.php and randomly named files with luci_ and zeta_ prefixes. [16]

The upgrade is the actual fix, and automatic background updates have already shrunk the affected population by shipping the patch without anyone clicking. [17]

What to watch

  • Whether attempt volume drops as background updates clear the patchable majority, or scanners pivot to the long tail of pinned and auto-update-disabled sites.
  • Whether a firewall signature emerges that handles the full range of pagename encodings Previdian saw, or the WAF stays a partial control.
  • Whether exploitation moves past pearcmd.php to other server-readable PHP files that satisfy the second precondition.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories