www.securityweek.com 24 Sept 2026, 07:12 UTC

WordPress Flaw Exploited Within Hours to Gain Remote Code Execution

WordPress Flaw Exploited Within Hours to Gain Remote Code Execution
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

A critical WordPress vulnerability was exploited within hours of its public disclosure, with attacks later progressing to active compromises, according to security firm Patchstack. Tracked as CVE-2026-87902 and rated 9.2 on the CVSS scale, the flaw is a path-traversal issue in page-template resolution that can allow unauthenticated attackers to include a chosen, readable local PHP file outside the active theme directories.

Remote code execution is possible when specific server and theme conditions are met, including an active parent or child theme whose top-level directory begins with “page-”.

The WordPress advisory says attackers can abuse the PEAR `pearcmd.php` tool when PHP’s `register_argc_argv` setting is enabled. The official PHP Docker image and default cPanel configurations using PHP before 8.5 are affected. Themes with the relevant layout include the legacy Twenty Twelve and Twenty Fourteen themes, as well as Neve, Hestia and Sydney. WordPress fixed the issue on 22 September in version 7.1.2 and backported the correction to releases as far back as 4.7.x.

Patchstack initially observed reconnaissance from a small group of IP addresses, followed by active compromises on 23 September. It said traffic later exceeded ten times the first evening’s volume and followed three stages: checking whether a site was vulnerable, testing for `pearcmd.php`, and using it to write PHP content and achieve remote code execution. Patchstack said the payloads matched the published patch and warned that exploitation is likely to increase because public scanning tools are available.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline