Daily Top · Vulnerabilities / Web

WordPress 7.1.2 closed an unauthenticated include. Attackers are already writing PHP to disk.

CVE-2026-87902 is page-template traversal to conditional RCE. Patchstack’s 23 September update is pearcmd file writes, not probes. It is not on KEV.

RWP Ventures · 2026-09-24 · event 2026-09-22 · 13 min read · priority 8.7

Bottom line up front

CONFIRMED WordPress 7.1.2, a security-only release, shipped on 22 September 2026 for CVE-2026-87902. The CNA is HackerOne. Published 22 September 16:44 UTC. An unauthenticated attacker can make get_page_template() include a readable local .php file outside the active theme directories. If the active theme and the server both meet the vendor pre-conditions, that include becomes remote code execution. WordPress’s own score is 9.2 CVSS 4.0 (AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N). CISA-ADP on the NVD record is 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H. CWE-98.

Do not collapse three facts.

  1. This is not on KEV. Catalog version 2026.09.23 (released 23 September 12:51 UTC, count 1721) has zero new rows since [yesterday’s F5 APM Daily Top](/posts/2026-09-23-f5-big-ip-apm-cve-2026-94127-kev/). CVE-2026-87902 is not in the JSON. CISA-ADP SSVC, frozen at 22 September 16:57 UTC, still reads exploitation none, automatable no, technical impact total. That SSVC stamp is older than Patchstack’s 23 September update. It is not a close.
  2. RCE is conditional. The include is not. The GHSA is explicit: the active child or parent theme needs a top-level directory whose name starts with page- (legacy Twenty Twelve and Twenty Fourteen; third-party examples Neve, Hestia, Sydney), and a readable .php target on the server. The well-known PEAR pearcmd.php path works when register_argc_argv is On — official PHP Docker images, and default cPanel on PHP before 8.5. Missing either pre-condition does not make the traversal go away. It only stops this particular jump to code execution.
  3. The traffic is past reconnaissance. Patchstack’s 23 September update: first request 22 September 11:49 UTC; traffic now more than ten times the first evening; public scanning tooling in circulation; attackers including pearcmd.php and using it to write PHP files to disk. BleepingComputer (23 September), SecurityWeek (24 September), and Help Net Security’s 24 September 05:30 ET update independently restated that shift. RWP is treating in-the-wild exploitation as CONFIRMED as Patchstack WAF telemetry, not as a CISA catalog fact.

This is not a re-run of [yesterday’s F5 KEV](/posts/2026-09-23-f5-big-ip-apm-cve-2026-94127-kev/). Different vendor, different plane, different clock. [Zyxel CVE-2026-7273](/posts/2026-09-22-zyxel-gs1900-cve-2026-7273-kev/) is due today.

FactRecord
CVECVE-2026-87902
ProductWordPress Core 4.7.0 through 7.1.1
Fix7.1.2; backports through 4.7.37
Vendor scoreCVSS 4.0 9.2 (GHSA)
CISA-ADP8.1 High; SSVC none / no / total as of 22 Sep 16:57 UTC
KEVNot listed (catalog 2026.09.23, count 1721)
ExploitationCONFIRMED as Patchstack telemetry; not a KEV criterion
Named CISA actorNone
OT / process impactNone claimed

What happened

John Blackbourn published the WordPress 7.1.2 news post on 22 September 2026. One fix. Robert Ressl is credited on the news post and as finder on the HackerOne CNA (Robert (ressl)). GHSA-7hp8-65ch-5whp is the technical advisory.

Affected trains in the GHSA, each closed the same day:

BranchAffected throughFixed in
7.17.1.17.1.2
7.07.0.57.0.6
6.96.9.86.9.9
6.86.8.96.8.10
6.7–4.7corresponding last unpatched6.7.9, 6.6.9, 6.5.12, 6.4.12, 6.3.12, 6.2.13, 6.1.14, 6.0.16, 5.9.18, 5.8.17, 5.7.19, 5.6.21, 5.5.22, 5.4.23, 5.3.25, 5.2.28, 5.1.26, 5.0.29, 4.9.33, 4.8.32, 4.7.37

Wordfence’s PSA restates that same backport list. WordPress’s news post reminds operators that only the current release is actively supported; the backports are courtesy. BleepingComputer notes branches before 4.6 are not getting a fix.

Ressl’s own write-up: private HackerOne report 20 July 2026 23:46 UTC, acknowledged 21 July, fix planned notice 15 September, public 22 September.

Patchstack’s 23 September update is the exploitation clock:

CloudLinux’s 23 September Imunify360 note: customers reporting active bulk scanning, and a public proof-of-concept in circulation. RWP is not linking a PoC.

Why it matters

WordPress is not a niche appliance. An unauthenticated include in Core, backported through 4.7, with scanners already past the fingerprint stage, is a mass-internet problem even when the RCE jump needs a page-* theme directory and a useful .php on disk. Those two pre-conditions are not exotic. Twenty Twelve / Twenty Fourteen still ship. Neve, Hestia, and Sydney are named in the GHSA because they are common. Official PHP Docker and default cPanel-before-8.5 are named because register_argc_argv is On there.

Two operational lies show up immediately:

  1. “We are on auto-update, so we can wait for KEV.” WordPress security releases do roll through background updates when that is enabled. Hosts that pinned a version, disabled auto-updates, or froze a 6.x/5.x train for a plugin are the denominator. CISA has not listed this CVE. Waiting for catalog 2026.09.24 is a choice, not a control.
  2. “Our theme is not Twenty Fourteen, so we are out.” The GHSA condition is a top-level directory name, not a theme brand. Child themes inherit the parent’s layout. Wordfence: verify the installed theme and the filesystem, because the advisory does not publish affected theme-version ranges.

CISA-ADP’s AC:H and SSVC Automatable: no describe the pre-conditions, not the probe. Stage-one traffic does not need PEAR. It only needs the traversal.

No public victim census. No named ransomware affiliate. No OT/process claim. A WordPress site in front of an industrial firm is still an IT CMS until someone shows a process impact.

Who / what is affected

AssetWhat to assumeStatus
WordPress 4.7.0–7.1.1 without the 22 Sep backportIn scope for the includeCONFIRMED vendor (GHSA + CNA)
WordPress 7.1.2 / matching backportOut of scope for this CVECONFIRMED vendor
Active theme with top-level page-* directory (Twenty Twelve, Twenty Fourteen, Neve, Hestia, Sydney, and unnamed others)RCE pre-condition 1CONFIRMED vendor examples; not an exhaustive list
Readable pearcmd.php + register_argc_argv=On (PHP Docker; cPanel PHP < 8.5)RCE pre-condition 2 for this jumpCONFIRMED vendor
PHP 8.5 default (register_argc_argv Off)This PEAR jump is harder; the include remainsASSESSED from vendor language + secondary reporting
WordPress < 4.7No backportCONFIRMED secondary (BleepingComputer); treat as unsupported
Named victimsNone publishedUNKNOWN
CISA KEV / ransomware fieldNot listedCONFIRMED catalog 2026.09.23
OT / ICS / processNot claimedNo evidence

Technical context

RWP is not reproducing request bodies, traversal encodings, or PEAR argv strings.

What the primary records give defenders:

ATT&CK mapping for what is stated:

Follow-on that is not claimed: a named APT, ransomware-Known, or OT/process impact.

Threat / exploitation status

ClaimStatusBasis
CVE published 22 Sep 16:44 UTC; GHSA Critical 9.2; CWE-98CONFIRMEDHackerOne CNA; GHSA
WordPress 7.1.2 + backports to 4.7.37CONFIRMEDwordpress.org news; GHSA; Wordfence
Unauthenticated include; RCE if both pre-conditionsCONFIRMEDGHSA
In-the-wild probing from 22 Sep 11:49 UTCCONFIRMED as PatchstackPatchstack 22/23 Sep
Shift to pearcmd file writes; 10× volume; public scannersCONFIRMED as Patchstack; REPORTED by BC / SecurityWeek / Help NetPatchstack 23 Sep update; 24 Sep secondaries
On CISA KEVNocatalog 2026.09.23 count 1721
CISA-ADP SSVC none / no / totalCONFIRMED as of 22 Sep 16:57 UTCCVE ADP; stale vs. 23 Sep telemetry
Named actor / victim countUNKNOWNNo census in vendor or Patchstack
Ransomware useUNKNOWNNot a KEV row
OT / physical-process impactNot claimedNo evidence

High confidence on: CVE ID, GHSA pre-conditions, 7.1.2 / backport table, CVSS 4.0 9.2, CISA-ADP 8.1, KEV absence, Patchstack first-seen 11:49 UTC, stage names, dropped filenames, /tmp caveat. Moderate confidence that internet-reachable unpatched sites with a page-* theme are already in the scanner denominator (10× volume + public tooling; no public census). Low confidence on CISA’s unpublished exploitation evidence (there is none on this CVE), on any victim identity, and on how many /tmp writes were later moved into the document root.

What defenders should do

  1. Patch Core to the 22 September backport on your branch. Then confirm the version string. 7.1.2, 7.0.6, 6.9.9, 6.8.10, or the matching 6.7–4.7 build in the table. Dashboard → Updates is the vendor path; auto-update is not inventory. Record internet exposure. A pinned composer/image tag is the usual miss.
  1. Inventory the two RCE pre-conditions anyway. Does the active parent or child theme have a top-level page-* directory? Is pearcmd.php on disk at the three paths Patchstack is seeing? Is register_argc_argv On? Those answers change hunting urgency. They do not replace the patch. The include is still a bug without them.
  1. Hunt the Patchstack combination, not a single 404. Access logs: pagename values that walk out of the theme, includes of wp-links-opml.php / feed-rss2.php / wp-cron.php, then pearcmd.php, then PEAR write activity. Filesystem: /tmp and /var/tmp for wp-pear-rce-flag.php, poc87902.php, luci_, zeta_. Escalate a write plus a later invoke. Do not close “no file in wp-content/uploads.”
  1. Do not wait for KEV, and do not treat a WAF rule as 7.1.2. Catalog 2026.09.23 does not list this CVE. CloudLinux said the Imunify360 virtual patch had not shipped as of 23 September. Patchstack’s rule protects Patchstack customers. Everyone else still needs the Core package.
  1. **Sequence the federal list that is on KEV. [Zyxel CVE-2026-7273](/posts/2026-09-22-zyxel-gs1900-cve-2026-7273-kev/) is due today. [F5 APM CVE-2026-94127](/posts/2026-09-23-f5-big-ip-apm-cve-2026-94127-kev/), Check Point CVE-2026-85102 / CVE-2026-93616, and Arista VeloCloud CVE-2026-93952 are due tomorrow**. Those clocks did not pause because WordPress started getting probed.

This is not an exploitation guide. Use WordPress 7.1.2 and the GHSA pre-condition inventory.

RWP assessment

Score 8.7. Unauthenticated Core include, a decade of affected branches, a same-day backport, and a documented jump from fingerprinting to file-write in under 24 hours. That is the highest-leverage new development since yesterday’s F5 KEV. It is not 8.9 because CISA has not listed it, RCE is conditional, and the current drop path Patchstack described is /tmp, not a durable web root shell.

It outranks a second day on CVE-2026-94127 (F5 APM, due tomorrow, already [yesterday’s Daily Top](/posts/2026-09-23-f5-big-ip-apm-cve-2026-94127-kev/)) because there is no material F5 development in catalog 2026.09.23 — 0 added, count still 1721. It outranks CVE-2026-7273 (Zyxel, due today) for the same reason: already [22 September’s Daily Top](/posts/2026-09-22-zyxel-gs1900-cve-2026-7273-kev/); the new fact is the deadline, not the bug. It outranks cPanel CVE-2026-87899 (authenticated CalDAV/CardDAV to root, patched 22 September in 11.134.0.57 / 11.136.0.41 / 11.138.0.8) because that bug needs an account on the box and has no public mass-exploitation telemetry comparable to Patchstack’s 10× CMS scan. It outranks Proofpoint’s UNK_CondorFiltration / TeamFiltration spray (5,714 accounts, 28 tenants, seven dormant service accounts, Chile-heavy) as identity hygiene with a small confirmed-compromise set, not a Core RCE being mass-scanned. It outranks ShinyHunters’ FBI/PeopleSoft claim (REPORTED, still unconfirmed by the Bureau in the records we have).

The failure mode to sand down is “conditional RCE means later.” The scanners did not wait. If the VIP still serves 7.1.1, or 6.8.9, or 4.9.32, you are in Patchstack’s denominator whether or not PEAR is on the box. If you only grepped wp-admin, you inventoried the wrong socket.

What we are watching

Sources

Sources

  1. WordPress — 7.1.2 security release
  2. WordPress — GHSA-7hp8-65ch-5whp
  3. CVE — CVE-2026-87902
  4. NVD — CVE-2026-87902
  5. CISA — KEV JSON feed catalog 2026.09.23
  6. CISA — Known Exploited Vulnerabilities Catalog
  7. Patchstack — CVE-2026-87902 attackers probing hours after the patch
  8. Patchstack — WordPress 7.1.2 security release LFI to RCE
  9. Wordfence — PSA critical unauthenticated path traversal in WordPress Core
  10. Robert Ressl — CVE-2026-87902 write-up
  11. BleepingComputer — Hackers start exploiting critical WordPress flaw for code execution
  12. SecurityWeek — Critical WordPress vulnerability exploited immediately after disclosure
  13. Help Net Security — WordPress 7.1.2 CVE-2026-87902
  14. The Hacker News — Attackers exploit WordPress CVE-2026-87902
  15. CloudLinux — CVE-2026-87902 Imunify360 note
  16. CISA — Adds four KEV 22 September 2026