WordPress path traversal exploited hours after disclosure
Attackers exploited WordPress path traversal bug CVE-2026-87902 within hours of disclosure to achieve remote code execution and active site compromises, Patchstack reports.
Attackers began exploiting a WordPress path traversal vulnerability tracked as CVE-2026-87902 within hours of the bug’s public disclosure, using the flaw to obtain remote code execution and to carry out site compromises, security firm Patchstack reports.
The defect is in WordPress’ page-template resolution function get_page_template(). WordPress’ advisory states: “An unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable local .php file outside the active theme directories. If relevant pre-conditions for both the server environment and the active theme are met, this can lead to RCE.” The vulnerability received a CVSS score of 9.2.
Exploitation requires two conditions. First, the top-level directory name of the active child or parent theme must begin with “page-“. Second, the web server account must be able to read a local .php file the attacker can target. WordPress identified affected themes that use this directory layout, including legacy themes Twenty Twelve and Twenty Fourteen and third-party themes such as Neve, Hestia and Sydney.
WordPress released a fix on September 22 in version 7.1.2 and backported the patch to earlier releases back to 4.7.x. Administrators are advised to apply WordPress 7.1.2 or the appropriate backported update for older sites.
The advisory describes how the inclusion can be combined with the known pearcmd.php PEAR-to-RCE transition to achieve remote code execution when PHP’s register_argc_argv setting is enabled. The advisory notes that the official PHP Docker image is affected and that default cPanel configurations running PHP versions prior to 8.5 can be vulnerable when the required conditions are present. Pearcmd.php is a command-line tool for managing PEAR packages that has been abused for code execution when PHP exposes command-line arguments.
Patchstack observed the first exploitation attempts within hours of disclosure and reported that the payloads matched the exact encoding addressed by the patch. Patchstack wrote that the payloads suggest the attackers built their exploits from the patch diff rather than from an independent discovery. Initial activity came from a small cluster of IP addresses and began as reconnaissance, and by September 23 the activity had escalated to active compromises.
The firm reported that traffic expanded rapidly after the initial probes, growing to more than ten times the volume seen on the first evening and reaching a wider set of sites. Patchstack described three stages in the observed attack chain: verification of whether a server is vulnerable, testing for the presence and readability of pearcmd.php, and using pearcmd.php to write PHP content and obtain remote code execution.
Administrators should update WordPress and backported releases, inspect theme directory names for the “page-” prefix, verify file permissions to restrict readable .php files for the web server account, and check for the presence of PEAR tools such as pearcmd.php. Teams should also review PHP configurations to disable register_argc_argv where it is not needed and monitor server logs for probe patterns matching the stages Patchstack described.







