// uncategorised

WordPress CVE-2026-87902 Exploited Hours After Disclosure

WordPress shipped a fix for a critical local file inclusion flaw on September 22. The first exploitation attempt was recorded the same day, at 11:49 UTC. Within hours it had moved from reconnaissance to attackers actually writing malicious PHP files to disk.

CVE-2026-87902 is unauthenticated, needs no valid account and no user interaction, and carries a CVSS score of 9.2. The bug sits in WordPress’s get_page_template() function: by abusing path traversal sequences in the pagename parameter, an attacker can force WordPress to load local PHP files from outside the intended template directory. Two conditions have to line up for it to fire: the active theme needs a top-level directory whose name starts with “page-“, and a readable local PHP file has to exist on the server that can be abused as a target, such as pearcmd.php.

Telemetry from Previdian logged 68 exploitation attempts starting September 23, with activity escalating from probing core files to actively including pearcmd.php to write new PHP files onto the server. WordPress patched the issue in version 7.1.2, with the fix backported all the way down to branch 4.7, which tells you how long this code path had been sitting there.

The window between disclosure and the first live exploitation attempt here was effectively zero. If you run WordPress and have not confirmed you are on 7.1.2 or later, treat that as the day’s first task, then check for the specific marker: new or unexpected PHP files written around the time of disclosure. Finding exactly this class of theme and plugin weakness before it becomes a same-day race is what our WordPress and CMS penetration testing is for.


// get started

Work with AgentOffense

Tell us about your target and goals. We’ll reply with scope and a fixed-price quote — usually within one business day.

./request_engagement