Aggressors swiftly commenced the exploitation of a significant flaw within WordPress merely hours following the release of its fix.
The vulnerability, designated as CVE-2026-87902, empowers an intruder devoid of login credentials to execute arbitrary code on a website’s server, albeit under specific circumstances.
WordPress addressed this vulnerability in version 7.1.2, released on September 22. Additionally, it rectified every previous version back to 4.7.
The security advisory classifies the issue as critical, bearing a CVSS score of 9.2, and acknowledges Robert Ressl for his pivotal reporting.
Initial attacks were detected at 11:49 UTC on that very day, as indicated by the WordPress security firm Patchstack.
Mechanism of the Attack
The vulnerability resides in the get_page_template() function, responsible for selecting the appropriate template file for a webpage.
An unauthenticated assailant can manipulate this function to load a readable PHP file from a location outside the active theme’s directories.
Two prerequisites must be satisfied for the exploitation to succeed. Firstly, the active theme needs to encompass a top-level directory that begins with “page-”.
Secondly, the server must retain an accessible PHP file for the attacker’s use. Thus far, the exploited file identified is pearcmd.php, a component of the PHP package manager PEAR.
Following reconnaissance of WordPress core files, attackers searched for pearcmd.php in three prevalent directories, as reported by Patchstack. Subsequently, they employed it to inject files into the server’s /tmp and /var/tmp directories.
The volume of malicious traffic escalated gradually, as articulated by Patchstack’s research lead, Dave Jong. Notably, it reached a zenith around midday UTC on September 23, eclipsing initial figures by a factor of more than ten.
Mitigating Damage through Auto-Updates
The cybersecurity firm Previdian documented 68 attempts at exploitation, as noted by The Hacker News. Ryan Dewhurst, its founder and CEO, asserted that the outlined conditions diminish the probability of successful breaches.
“Due to WordPress’s auto-update feature being enabled by default, we are likely to witness extensive exploitation attempts, yet relatively few actual compromises,” Dewhurst conveyed to The Hacker News.
Website administrators are strongly advised to update to version 7.1.2 or the respective patched release for their version.
Furthermore, Patchstack recommends restricting “..” sequences within the pagename parameter. Disabling PHP’s register_argc_argv setting effectively nullifies the pearcmd exploitation step.
A Series of Recently Exploited Vulnerabilities
This WordPress vulnerability marks the latest incidence within a string of flaws that have been exploited shortly after their disclosure.

Cisco issued a warning earlier this month informing that hackers were targeting a high-severity ISE vulnerability.
Moreover, Microsoft’s September update rectified a record 974 vulnerabilities, with two under direct attack. Additionally, Google addressed a flaw in Chrome’s V8 engine that has been deployed in ongoing attacks.
Source link: Thenextweb.com.



