For WordPress site owners, the time between a vulnerability being disclosed and attackers trying to exploit it is getting dangerously short. That became clear again when hackers began targeting a critical WordPress security flaw just hours after its details became public.
Tracked as CVE-2026-87902, the vulnerability carries a CVSS score of 9.2 and affects WordPress versions 4.7.0 through 7.1.1.
The vulnerability stems from how WordPress resolves page templates. In certain setups, an unauthenticated attacker can exploit a path-traversal flaw to trick WordPress into loading a readable PHP file from outside the active theme’s directory.
The impact can go much further than simply accessing a file. On vulnerable server configurations, attackers may be able to turn the flaw into remote code execution (RCE), potentially allowing them to run malicious commands or scripts on the affected server.
WordPress released a security fix on September 22, 2026, with version 7.1.2 and also backported the patch to supported older branches, including versions going back to the 4.7 series. WordPress strongly recommends that site owners install the latest security update as soon as possible.
But attackers wasted little time. According to Patchstack, exploitation attempts were detected within hours of the vulnerability being publicly disclosed. Researchers observed attackers going beyond basic scanning and attempting to abuse pearcmd.php, a PEAR component that may be present on PHP servers.
By abusing this component, attackers could potentially create malicious PHP files on a server, turning the original vulnerability into a much more serious system compromise.
However, the vulnerability cannot be exploited on every WordPress installation. An attack requires specific server and theme configurations, including a page- directory in the active theme and access to a readable PHP file that can be leveraged by the attacker.
What makes this incident particularly concerning is the speed of exploitation. Attackers appear to have moved from public disclosure to real-world exploitation attempts in a matter of hours, leaving website administrators with very little time to react.
Let’s refine your stalking skills; go through our Instagram and LinkedIn.