WordPress 7.1.2 closed an unauthenticated include. Attackers are already writing PHP to disk.
CVE-2026-87902 is page-template traversal to conditional RCE. Patchstack’s 23 September update is pearcmd file writes, not probes. It is not on KEV.
Bottom line up front
CONFIRMED WordPress 7.1.2, a security-only release, shipped on 22 September 2026 for CVE-2026-87902. The CNA is HackerOne. Published 22 September 16:44 UTC. An unauthenticated attacker can make get_page_template() include a readable local .php file outside the active theme directories. If the active theme and the server both meet the vendor pre-conditions, that include becomes remote code execution. WordPress’s own score is 9.2 CVSS 4.0 (AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N). CISA-ADP on the NVD record is 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H. CWE-98.
Do not collapse three facts.
- This is not on KEV. Catalog version
2026.09.23(released 23 September 12:51 UTC, count 1721) has zero new rows since [yesterday’s F5 APM Daily Top](/posts/2026-09-23-f5-big-ip-apm-cve-2026-94127-kev/). CVE-2026-87902 is not in the JSON. CISA-ADP SSVC, frozen at 22 September 16:57 UTC, still reads exploitation none, automatable no, technical impact total. That SSVC stamp is older than Patchstack’s 23 September update. It is not a close. - RCE is conditional. The include is not. The GHSA is explicit: the active child or parent theme needs a top-level directory whose name starts with
page-(legacy Twenty Twelve and Twenty Fourteen; third-party examples Neve, Hestia, Sydney), and a readable.phptarget on the server. The well-known PEARpearcmd.phppath works whenregister_argc_argvis On — official PHP Docker images, and default cPanel on PHP before 8.5. Missing either pre-condition does not make the traversal go away. It only stops this particular jump to code execution. - The traffic is past reconnaissance. Patchstack’s 23 September update: first request 22 September 11:49 UTC; traffic now more than ten times the first evening; public scanning tooling in circulation; attackers including
pearcmd.phpand using it to write PHP files to disk. BleepingComputer (23 September), SecurityWeek (24 September), and Help Net Security’s 24 September 05:30 ET update independently restated that shift. RWP is treating in-the-wild exploitation as CONFIRMED as Patchstack WAF telemetry, not as a CISA catalog fact.
This is not a re-run of [yesterday’s F5 KEV](/posts/2026-09-23-f5-big-ip-apm-cve-2026-94127-kev/). Different vendor, different plane, different clock. [Zyxel CVE-2026-7273](/posts/2026-09-22-zyxel-gs1900-cve-2026-7273-kev/) is due today.
| Fact | Record |
|---|---|
| CVE | CVE-2026-87902 |
| Product | WordPress Core 4.7.0 through 7.1.1 |
| Fix | 7.1.2; backports through 4.7.37 |
| Vendor score | CVSS 4.0 9.2 (GHSA) |
| CISA-ADP | 8.1 High; SSVC none / no / total as of 22 Sep 16:57 UTC |
| KEV | Not listed (catalog 2026.09.23, count 1721) |
| Exploitation | CONFIRMED as Patchstack telemetry; not a KEV criterion |
| Named CISA actor | None |
| OT / process impact | None claimed |
What happened
John Blackbourn published the WordPress 7.1.2 news post on 22 September 2026. One fix. Robert Ressl is credited on the news post and as finder on the HackerOne CNA (Robert (ressl)). GHSA-7hp8-65ch-5whp is the technical advisory.
Affected trains in the GHSA, each closed the same day:
| Branch | Affected through | Fixed in |
|---|---|---|
| 7.1 | 7.1.1 | 7.1.2 |
| 7.0 | 7.0.5 | 7.0.6 |
| 6.9 | 6.9.8 | 6.9.9 |
| 6.8 | 6.8.9 | 6.8.10 |
| 6.7–4.7 | corresponding last unpatched | 6.7.9, 6.6.9, 6.5.12, 6.4.12, 6.3.12, 6.2.13, 6.1.14, 6.0.16, 5.9.18, 5.8.17, 5.7.19, 5.6.21, 5.5.22, 5.4.23, 5.3.25, 5.2.28, 5.1.26, 5.0.29, 4.9.33, 4.8.32, 4.7.37 |
Wordfence’s PSA restates that same backport list. WordPress’s news post reminds operators that only the current release is actively supported; the backports are courtesy. BleepingComputer notes branches before 4.6 are not getting a fix.
Ressl’s own write-up: private HackerOne report 20 July 2026 23:46 UTC, acknowledged 21 July, fix planned notice 15 September, public 22 September.
Patchstack’s 23 September update is the exploitation clock:
- Stage one (still the bulk of traffic): include a harmless core file so the response fingerprints whether the traversal is live.
wp-links-opml.phpmost common;wp-includes/feed-rss2.phpnow in volume; alsowp-cron.php,wp-includes/functions.php,wp-login.php,install.php. - Stage two: include
pearcmd.phpand pass a PEAR command through the query string (config-show) to test whetherregister_argc_argvis On. Three filesystem locations in the wild:/usr/local/lib/php/pearcmd.php,/usr/share/php/pearcmd.php,/usr/share/pear/pearcmd.php. - Stage three: swap to a PEAR write (
config-create) and drop a.phpfile under/tmpor/var/tmp. Filenames Patchstack published:wp-pear-rce-flag.php,poc87902.php,luci_<random>.php,zeta_<random>.php. Some writes are a marker string. Others are a short tag that runs a shell command on access. Patchstack’s own caveat, which RWP is keeping: a file under/tmpis usually not web-reachable, so this is proof of execution more than a persistent web shell. It is still code execution on the host.
CloudLinux’s 23 September Imunify360 note: customers reporting active bulk scanning, and a public proof-of-concept in circulation. RWP is not linking a PoC.
Why it matters
WordPress is not a niche appliance. An unauthenticated include in Core, backported through 4.7, with scanners already past the fingerprint stage, is a mass-internet problem even when the RCE jump needs a page-* theme directory and a useful .php on disk. Those two pre-conditions are not exotic. Twenty Twelve / Twenty Fourteen still ship. Neve, Hestia, and Sydney are named in the GHSA because they are common. Official PHP Docker and default cPanel-before-8.5 are named because register_argc_argv is On there.
Two operational lies show up immediately:
- “We are on auto-update, so we can wait for KEV.” WordPress security releases do roll through background updates when that is enabled. Hosts that pinned a version, disabled auto-updates, or froze a 6.x/5.x train for a plugin are the denominator. CISA has not listed this CVE. Waiting for catalog
2026.09.24is a choice, not a control. - “Our theme is not Twenty Fourteen, so we are out.” The GHSA condition is a top-level directory name, not a theme brand. Child themes inherit the parent’s layout. Wordfence: verify the installed theme and the filesystem, because the advisory does not publish affected theme-version ranges.
CISA-ADP’s AC:H and SSVC Automatable: no describe the pre-conditions, not the probe. Stage-one traffic does not need PEAR. It only needs the traversal.
No public victim census. No named ransomware affiliate. No OT/process claim. A WordPress site in front of an industrial firm is still an IT CMS until someone shows a process impact.
Who / what is affected
| Asset | What to assume | Status |
|---|---|---|
| WordPress 4.7.0–7.1.1 without the 22 Sep backport | In scope for the include | CONFIRMED vendor (GHSA + CNA) |
| WordPress 7.1.2 / matching backport | Out of scope for this CVE | CONFIRMED vendor |
Active theme with top-level page-* directory (Twenty Twelve, Twenty Fourteen, Neve, Hestia, Sydney, and unnamed others) | RCE pre-condition 1 | CONFIRMED vendor examples; not an exhaustive list |
Readable pearcmd.php + register_argc_argv=On (PHP Docker; cPanel PHP < 8.5) | RCE pre-condition 2 for this jump | CONFIRMED vendor |
PHP 8.5 default (register_argc_argv Off) | This PEAR jump is harder; the include remains | ASSESSED from vendor language + secondary reporting |
| WordPress < 4.7 | No backport | CONFIRMED secondary (BleepingComputer); treat as unsupported |
| Named victims | None published | UNKNOWN |
| CISA KEV / ransomware field | Not listed | CONFIRMED catalog 2026.09.23 |
| OT / ICS / process | Not claimed | No evidence |
Technical context
RWP is not reproducing request bodies, traversal encodings, or PEAR argv strings.
What the primary records give defenders:
- Primitive. Unauthenticated HTTP to a site that still has the unpatched
get_page_template()path. The decoded page name was added to template candidates without the later_wp_is_template_path_allowed()/validate_file()gate (CloudLinux restatement of the patch). Local file inclusion. Conditional RCE. - Prerequisite for RCE via PEAR. Theme
page-*directory and a useful readable.phpandregister_argc_argv=Onfor the argv hand-off. Reachability is the front of the CMS, not wp-admin. - Hunting combination (Patchstack). Access-log hits that pair a
pagenametraversal with core-file includes (fingerprint), thenpearcmd.phpfrom the three paths above, then writes under/tmpand/var/tmpwith the filenames in the table. Any one of those alone is not a confirmed compromise. The write with a shell-on-access tag is. - WAF is not the patch. Patchstack RapidMitigate and pending Imunify360 WPT-3057 (CloudLinux: not shipped as of 23 September) buy time. WordPress 7.1.2 or the branch backport is the close.
ATT&CK mapping for what is stated:
- Exploit public-facing application (T1190) against WordPress front-end template resolution.
- Command execution (T1059 class) after a successful PEAR write, when the dropped file is later invoked.
- Web shell (T1505.003) is a follow-on risk. Patchstack has not claimed a durable document-root shell as the current drop pattern.
Follow-on that is not claimed: a named APT, ransomware-Known, or OT/process impact.
Threat / exploitation status
| Claim | Status | Basis |
|---|---|---|
| CVE published 22 Sep 16:44 UTC; GHSA Critical 9.2; CWE-98 | CONFIRMED | HackerOne CNA; GHSA |
| WordPress 7.1.2 + backports to 4.7.37 | CONFIRMED | wordpress.org news; GHSA; Wordfence |
| Unauthenticated include; RCE if both pre-conditions | CONFIRMED | GHSA |
| In-the-wild probing from 22 Sep 11:49 UTC | CONFIRMED as Patchstack | Patchstack 22/23 Sep |
| Shift to pearcmd file writes; 10× volume; public scanners | CONFIRMED as Patchstack; REPORTED by BC / SecurityWeek / Help Net | Patchstack 23 Sep update; 24 Sep secondaries |
| On CISA KEV | No | catalog 2026.09.23 count 1721 |
| CISA-ADP SSVC none / no / total | CONFIRMED as of 22 Sep 16:57 UTC | CVE ADP; stale vs. 23 Sep telemetry |
| Named actor / victim count | UNKNOWN | No census in vendor or Patchstack |
| Ransomware use | UNKNOWN | Not a KEV row |
| OT / physical-process impact | Not claimed | No evidence |
High confidence on: CVE ID, GHSA pre-conditions, 7.1.2 / backport table, CVSS 4.0 9.2, CISA-ADP 8.1, KEV absence, Patchstack first-seen 11:49 UTC, stage names, dropped filenames, /tmp caveat. Moderate confidence that internet-reachable unpatched sites with a page-* theme are already in the scanner denominator (10× volume + public tooling; no public census). Low confidence on CISA’s unpublished exploitation evidence (there is none on this CVE), on any victim identity, and on how many /tmp writes were later moved into the document root.
What defenders should do
- Patch Core to the 22 September backport on your branch. Then confirm the version string. 7.1.2, 7.0.6, 6.9.9, 6.8.10, or the matching 6.7–4.7 build in the table. Dashboard → Updates is the vendor path; auto-update is not inventory. Record internet exposure. A pinned composer/image tag is the usual miss.
- Inventory the two RCE pre-conditions anyway. Does the active parent or child theme have a top-level
page-*directory? Ispearcmd.phpon disk at the three paths Patchstack is seeing? Isregister_argc_argvOn? Those answers change hunting urgency. They do not replace the patch. The include is still a bug without them.
- Hunt the Patchstack combination, not a single 404. Access logs:
pagenamevalues that walk out of the theme, includes ofwp-links-opml.php/feed-rss2.php/wp-cron.php, thenpearcmd.php, then PEAR write activity. Filesystem:/tmpand/var/tmpforwp-pear-rce-flag.php,poc87902.php,luci_,zeta_. Escalate a write plus a later invoke. Do not close “no file inwp-content/uploads.”
- Do not wait for KEV, and do not treat a WAF rule as 7.1.2. Catalog
2026.09.23does not list this CVE. CloudLinux said the Imunify360 virtual patch had not shipped as of 23 September. Patchstack’s rule protects Patchstack customers. Everyone else still needs the Core package.
- **Sequence the federal list that is on KEV. [Zyxel CVE-2026-7273](/posts/2026-09-22-zyxel-gs1900-cve-2026-7273-kev/) is due today. [F5 APM CVE-2026-94127](/posts/2026-09-23-f5-big-ip-apm-cve-2026-94127-kev/), Check Point CVE-2026-85102 / CVE-2026-93616, and Arista VeloCloud CVE-2026-93952 are due tomorrow**. Those clocks did not pause because WordPress started getting probed.
This is not an exploitation guide. Use WordPress 7.1.2 and the GHSA pre-condition inventory.
RWP assessment
Score 8.7. Unauthenticated Core include, a decade of affected branches, a same-day backport, and a documented jump from fingerprinting to file-write in under 24 hours. That is the highest-leverage new development since yesterday’s F5 KEV. It is not 8.9 because CISA has not listed it, RCE is conditional, and the current drop path Patchstack described is /tmp, not a durable web root shell.
It outranks a second day on CVE-2026-94127 (F5 APM, due tomorrow, already [yesterday’s Daily Top](/posts/2026-09-23-f5-big-ip-apm-cve-2026-94127-kev/)) because there is no material F5 development in catalog 2026.09.23 — 0 added, count still 1721. It outranks CVE-2026-7273 (Zyxel, due today) for the same reason: already [22 September’s Daily Top](/posts/2026-09-22-zyxel-gs1900-cve-2026-7273-kev/); the new fact is the deadline, not the bug. It outranks cPanel CVE-2026-87899 (authenticated CalDAV/CardDAV to root, patched 22 September in 11.134.0.57 / 11.136.0.41 / 11.138.0.8) because that bug needs an account on the box and has no public mass-exploitation telemetry comparable to Patchstack’s 10× CMS scan. It outranks Proofpoint’s UNK_CondorFiltration / TeamFiltration spray (5,714 accounts, 28 tenants, seven dormant service accounts, Chile-heavy) as identity hygiene with a small confirmed-compromise set, not a Core RCE being mass-scanned. It outranks ShinyHunters’ FBI/PeopleSoft claim (REPORTED, still unconfirmed by the Bureau in the records we have).
The failure mode to sand down is “conditional RCE means later.” The scanners did not wait. If the VIP still serves 7.1.1, or 6.8.9, or 4.9.32, you are in Patchstack’s denominator whether or not PEAR is on the box. If you only grepped wp-admin, you inventoried the wrong socket.
What we are watching
- Whether CISA adds CVE-2026-87902 to KEV and whether SSVC flips off
none. - Whether Patchstack, Wordfence, or a hoster publishes a victim count, a document-root shell pattern, or a ransomware-use flag.
- Whether Imunify360 WPT-3057 ships, and whether other WAF vendors document coverage without claiming it replaces 7.1.2.
- Friday’s close rate on F5 94127, Check Point 85102/93616, and Arista 93952 — especially Arista 6.1 / 7.0 trains still without a listed fix.
- Any attempt to treat a compromised WordPress front-end at an industrial firm as OT impact without process evidence.
Sources
- WordPress — 7.1.2 security release (22 September 2026)
- WordPress — GHSA-7hp8-65ch-5whp
- CVE.org — CVE-2026-87902
- NVD — CVE-2026-87902
- CISA KEV JSON feed
- CISA Known Exploited Vulnerabilities Catalog
- Patchstack — attackers probing hours after the patch (updated 23 September 2026)
- Patchstack — 7.1.2 LFI to RCE
- Wordfence — PSA, 22 September 2026
- Robert Ressl — CVE-2026-87902
- BleepingComputer — exploiting for code execution (23 September 2026)
- SecurityWeek — exploited immediately after disclosure (24 September 2026)
- Help Net Security — 7.1.2 (updated 24 September 2026)
- The Hacker News — attackers exploit CVE-2026-87902
- CloudLinux — Imunify360 note, 23 September 2026
- CISA — Adds four KEV (22 September 2026)
- [RWP Daily Top, 23 September 2026 — F5 CVE-2026-94127](/posts/2026-09-23-f5-big-ip-apm-cve-2026-94127-kev/)
- [RWP Daily Top, 22 September 2026 — Zyxel CVE-2026-7273](/posts/2026-09-22-zyxel-gs1900-cve-2026-7273-kev/)
Sources
- WordPress — 7.1.2 security release
- WordPress — GHSA-7hp8-65ch-5whp
- CVE — CVE-2026-87902
- NVD — CVE-2026-87902
- CISA — KEV JSON feed catalog 2026.09.23
- CISA — Known Exploited Vulnerabilities Catalog
- Patchstack — CVE-2026-87902 attackers probing hours after the patch
- Patchstack — WordPress 7.1.2 security release LFI to RCE
- Wordfence — PSA critical unauthenticated path traversal in WordPress Core
- Robert Ressl — CVE-2026-87902 write-up
- BleepingComputer — Hackers start exploiting critical WordPress flaw for code execution
- SecurityWeek — Critical WordPress vulnerability exploited immediately after disclosure
- Help Net Security — WordPress 7.1.2 CVE-2026-87902
- The Hacker News — Attackers exploit WordPress CVE-2026-87902
- CloudLinux — CVE-2026-87902 Imunify360 note
- CISA — Adds four KEV 22 September 2026