A serious vulnerability in WordPress came under attack shortly after being patched

Try Our Free Tools!
Master the web with Free Tools that work as hard as you do. From Text Analysis to Website Management, we empower your digital journey with expert guidance and free, powerful tools.

Aggressors swiftly commenced the exploitation of a significant flaw within WordPress merely hours following the release of its fix.

The vulnerability, designated as CVE-2026-87902, empowers an intruder devoid of login credentials to execute arbitrary code on a website’s server, albeit under specific circumstances.

WordPress addressed this vulnerability in version 7.1.2, released on September 22. Additionally, it rectified every previous version back to 4.7.

The security advisory classifies the issue as critical, bearing a CVSS score of 9.2, and acknowledges Robert Ressl for his pivotal reporting.

Initial attacks were detected at 11:49 UTC on that very day, as indicated by the WordPress security firm Patchstack.

Mechanism of the Attack

The vulnerability resides in the get_page_template() function, responsible for selecting the appropriate template file for a webpage.

An unauthenticated assailant can manipulate this function to load a readable PHP file from a location outside the active theme’s directories.

Two prerequisites must be satisfied for the exploitation to succeed. Firstly, the active theme needs to encompass a top-level directory that begins with “page-”.

Secondly, the server must retain an accessible PHP file for the attacker’s use. Thus far, the exploited file identified is pearcmd.php, a component of the PHP package manager PEAR.

Following reconnaissance of WordPress core files, attackers searched for pearcmd.php in three prevalent directories, as reported by Patchstack. Subsequently, they employed it to inject files into the server’s /tmp and /var/tmp directories.

The volume of malicious traffic escalated gradually, as articulated by Patchstack’s research lead, Dave Jong. Notably, it reached a zenith around midday UTC on September 23, eclipsing initial figures by a factor of more than ten.

Mitigating Damage through Auto-Updates

The cybersecurity firm Previdian documented 68 attempts at exploitation, as noted by The Hacker News. Ryan Dewhurst, its founder and CEO, asserted that the outlined conditions diminish the probability of successful breaches.

“Due to WordPress’s auto-update feature being enabled by default, we are likely to witness extensive exploitation attempts, yet relatively few actual compromises,” Dewhurst conveyed to The Hacker News.

Website administrators are strongly advised to update to version 7.1.2 or the respective patched release for their version.

Furthermore, Patchstack recommends restricting “..” sequences within the pagename parameter. Disabling PHP’s register_argc_argv setting effectively nullifies the pearcmd exploitation step.

A Series of Recently Exploited Vulnerabilities

This WordPress vulnerability marks the latest incidence within a string of flaws that have been exploited shortly after their disclosure.

white and blue printer paper

Cisco issued a warning earlier this month informing that hackers were targeting a high-severity ISE vulnerability.

Moreover, Microsoft’s September update rectified a record 974 vulnerabilities, with two under direct attack. Additionally, Google addressed a flaw in Chrome’s V8 engine that has been deployed in ongoing attacks.

Source link: Thenextweb.com.

Disclosure: This article is for general information only and is based on publicly available sources. We aim for accuracy but can't guarantee it. The views expressed are the author's and may not reflect those of the publication. Some content was created with help from AI and reviewed by a human for clarity and accuracy. We value transparency and encourage readers to verify important details. This article may include affiliate links. If you buy something through them, we may earn a small commission — at no extra cost to you. All information is carefully selected and reviewed to ensure it's helpful and trustworthy.

Reported By

Souvik Banerjee

I’m Souvik Banerjee from Kolkata, India. As a Marketing Manager at RS Web Solutions (RSWEBSOLS), I specialize in digital marketing, SEO, programming, web development, and eCommerce strategies. I also write tutorials and tech articles that help professionals better understand web technologies.
Share the Love
Related News Worth Reading