WordPress CVE-2026-87902: Critical RCE Flaw Exploited, Patch Now
WordPress 7.1.2 fixes a critical, unauthenticated path-traversal bug in get_page_template() that attackers began exploiting within hours of disclosure. CISA has ordered federal agencies to patch fast.

WordPress has shipped an emergency fix, and site owners need to act now. On September 22, 2026, the WordPress security team released version 7.1.2 to patch CVE-2026-87902, a critical, unauthenticated path-traversal vulnerability in WordPress Core's template-resolution code that can lead to remote code execution. The bug has existed since WordPress 4.7 in 2016, attackers were probing for it within hours of the patch going out, and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added it to its Known Exploited Vulnerabilities (KEV) catalog. If you run WordPress and haven't updated in the last week, treat this as urgent.
CVE ID: CVE-2026-87902
Severity: Critical — CVSS v4.0 base score 9.2 (Vector: AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
Vulnerability type: Unauthenticated path traversal / local file inclusion in get_page_template(), potentially leading to remote code execution
Affected versions: WordPress Core 4.7 through 7.1.1 (all branches back to 4.7.0)
Patched versions: 7.1.2 (current), with backports to 7.0.6, 6.9.9, 6.8.10, 6.7.9, 6.6.9, 6.5.12, 6.4.12, 6.3.12, 6.2.13, 6.1.14, 6.0.16, 5.9.18, 5.8.17, 5.7.19, 5.6.21, 5.5.22, 5.4.23, 5.3.25, 5.2.28, 5.1.26, 5.0.29, 4.9.33, 4.8.32 and 4.7.37
Discovered/reported by: Security researcher Robert Ressl, via WordPress's HackerOne bug-bounty program
CISA KEV status: Added to the KEV catalog on 2026-09-25, with a remediation due date of 2026-09-28 for U.S. federal agencies
What happened
WordPress's security team disclosed and patched CVE-2026-87902 on September 22, 2026, as part of the WordPress 7.1.2 security release. According to WordPress's own release documentation, "this release features one security fix," described as "an unauthenticated path traversal issue in page-template resolution leading to conditional remote code execution," credited to researcher Robert Ressl. The advisory was also published by the WordPress security team as GHSA-7hp8-65ch-5whp on the wordpress-develop GitHub repository, which lists the flaw as critical with a CVSS v4.0 score of 9.2.
What makes this release unusual is its reach. WordPress doesn't just patch the current 7.1 branch for a critical, unauthenticated bug — it backports fixes to every legacy branch still receiving security support. In this case that meant simultaneous point releases across 23 separate version branches, all the way back to WordPress 4.7.37, closing a hole that had sat in WordPress Core's codebase for nearly a decade.
What CVE-2026-87902 actually is
The vulnerability lives in get_page_template(), the WordPress Core function responsible for resolving which template file to load for a given page. Per the GHSA advisory, an unauthenticated attacker can manipulate the pagename parameter — together with a valid page_id — using double-encoded path-traversal sequences so that WordPress's template-resolution logic includes a readable local .php file that sits outside the active theme's directories. Because the function runs unauthenticated, on the front end, no login or account of any kind is required to trigger it.
On its own, tricking WordPress into including an arbitrary local PHP file is a serious information-disclosure and file-inclusion bug. Whether it escalates to full remote code execution depends on two additional, independently documented conditions:
- Theme structure: the site's active theme must contain a top-level directory whose name starts with the prefix
page-(for example, apage-templatesfolder). Several popular themes, including older WordPress defaults and a number of third-party themes, use this convention. - A reachable, writable PHP entry point: the server needs some other readable
.phpfile the attacker can leverage. Researchers demonstrated a practical chain usingpearcmd.php— a command-line utility bundled with PHP's PEAR package manager — when the PHPregister_argc_argvsetting is enabled. That combination lets an attacker swap PEAR'sconfig-showargument forconfig-create, whichpearcmd.phpwill use to write an attacker-controlled PHP file to disk, which the traversal bug then executes.
pearcmd.php ships in the official PHP Docker images and is present by default in many common cPanel PHP configurations, which is why security researchers have flagged this as a realistic, not theoretical, RCE path on a meaningful slice of the WordPress hosting base.
Who is affected
Every WordPress Core installation from version 4.7.0 up to and including 7.1.1 is affected, regardless of which plugins or themes are installed, since the vulnerable code sits in Core itself. WordPress powers a large share of all websites, and this bug has been present in every release for almost ten years, so the exposed population is large by default — actual exploitability on any given site still depends on the theme and server conditions described above, but the flaw is trivially reachable and requires no authentication, which is why WordPress treated it as critical for the entire install base rather than a narrow edge case.
| Branch | Affected versions | Patched version |
|---|---|---|
| 7.1 | 7.1.0 – 7.1.1 | 7.1.2 |
| 7.0 | up to 7.0.5 | 7.0.6 |
| 6.9 | up to 6.9.8 | 6.9.9 |
| 6.8 | up to 6.8.9 | 6.8.10 |
| 6.7 | up to 6.7.8 | 6.7.9 |
| 6.6 | up to 6.6.8 | 6.6.9 |
| 6.5 | up to 6.5.11 | 6.5.12 |
| 6.4 | up to 6.4.11 | 6.4.12 |
| 6.3 | up to 6.3.11 | 6.3.12 |
| 6.2 | up to 6.2.12 | 6.2.13 |
| 6.1 | up to 6.1.13 | 6.1.14 |
| 6.0 | up to 6.0.15 | 6.0.16 |
| 5.9 | up to 5.9.17 | 5.9.18 |
| 5.8 | up to 5.8.16 | 5.8.17 |
| 5.7 | up to 5.7.18 | 5.7.19 |
| 5.6 | up to 5.6.20 | 5.6.21 |
| 5.5 | up to 5.5.21 | 5.5.22 |
| 5.4 | up to 5.4.22 | 5.4.23 |
| 5.3 | up to 5.3.24 | 5.3.25 |
| 5.2 | up to 5.2.27 | 5.2.28 |
| 5.1 | up to 5.1.25 | 5.1.26 |
| 5.0 | up to 5.0.28 | 5.0.29 |
| 4.9 | up to 4.9.32 | 4.9.33 |
| 4.8 | up to 4.8.31 | 4.8.32 |
| 4.7 | up to 4.7.36 | 4.7.37 |
Sites still running WordPress 4.6 or earlier receive no fix — those branches are past end-of-life for security support and should be upgraded to a current, supported release rather than patched in place.
Active exploitation: what attackers are doing
This is not a theoretical bug sitting quietly in a disclosure report. According to BleepingComputer's reporting, malicious requests targeting the flaw began arriving within hours of the September 22 patch, and attack traffic increased roughly tenfold by the following day as opportunistic scanning gave way to actual payload delivery. Attackers have been observed abusing the pearcmd.php chain described above to write small PHP web shells to temporary directories such as /tmp and /var/tmp, with file names like wp-pear-rce-flag.php or randomized names, which then let them execute arbitrary commands on compromised hosts.
The pattern is a familiar one for critical, unauthenticated WordPress Core bugs: the public release of a patch effectively hands reverse-engineers a roadmap to the vulnerable code, and mass scanning for unpatched sites typically follows within a day or two. Multiple independent outlets, including SecurityAffairs, have since confirmed that exploitation is ongoing and that CISA responded by fast-tracking the flaw into its KEV catalog.
CISA's Known Exploited Vulnerabilities listing
CISA added CVE-2026-87902 to its Known Exploited Vulnerabilities catalog on 2026-09-25, listing "WordPress" as the vendor and "Core" as the product, and describing it as a "WordPress Core Remote File Inclusion Vulnerability." The KEV entry sets a remediation due date of 2026-09-28 for U.S. federal civilian agencies under Binding Operational Directive 26-04, which governs prioritizing security updates based on risk. A KEV listing doesn't legally bind private organizations, but CISA's standing guidance is that any organization running an affected product should treat a KEV entry as a signal to patch on an equivalently urgent timeline — in this case, a matter of days, not weeks. You can also check the CVE's National Vulnerability Database entry for the CVSS scoring detail and CPE ranges.
Timeline
| Date | Event |
|---|---|
| September 22, 2026 | WordPress releases version 7.1.2 (and 23 backported branch releases) patching CVE-2026-87902 |
| September 22, 2026 (same day) | First exploitation attempts observed in the wild, according to BleepingComputer |
| September 23, 2026 | Attack volume increases roughly tenfold as scanning shifts to payload delivery |
| September 25, 2026 | CISA adds CVE-2026-87902 to its Known Exploited Vulnerabilities catalog |
| September 28, 2026 | CISA's remediation due date for U.S. federal civilian agencies |
How to check if your site is vulnerable
Start with the version number: log into wp-admin and check the WordPress version shown on the Dashboard, or under Dashboard > Updates. If it's earlier than the patched release for your branch (see the table above), your site is vulnerable to CVE-2026-87902 regardless of which theme or plugins you run, since the flaw lives in WordPress Core's /wp-includes/template.php file. WordPress's own changelog for the 7.1.2 release confirms that file as the only one revised to fix this issue, so if you have any doubt, you can compare its contents against a known-patched copy of WordPress Core.
If you manage many sites, a managed WordPress host or security plugin that reports Core version numbers across your fleet will get you an answer faster than checking each dashboard individually. Hosts that auto-apply minor Core security releases — as most reputable managed WordPress hosts do — should already be patched, but it's worth confirming rather than assuming, especially on self-managed VPS or dedicated-server installs.
How to patch
The fix is a standard WordPress Core update, and most sites can apply it in minutes:
- In wp-admin, go to Dashboard > Updates and apply the update if one is offered, or update to the latest version in your branch (7.1.2, or the corresponding patched release for your branch listed above).
- If automatic background updates for minor/security releases are enabled (the WordPress default for point releases), many sites will already have received 7.1.2 automatically — check your version to confirm.
- Sites managed via WP-CLI can run
wp core update, or update to a specific patched version withwp core update --version=7.1.2. - You can also download the patched package directly from the WordPress.org releases page and apply it manually if you manage updates outside the dashboard.
- After updating, verify the version number shown in wp-admin matches the patched release for your branch.
There's no reason to jump multiple major versions just to get this fix — WordPress backported it all the way to 4.7.37 specifically so sites on older, still-supported branches don't have to do a risky major-version migration under time pressure. Update within your current branch first; consider a broader upgrade plan separately, on your own schedule.
If you can't patch immediately: mitigations
Patching is the only fix that closes the vulnerability itself, and it should happen as soon as possible. If a full Core update genuinely cannot happen right away — for example, on a heavily customized site that needs regression testing first — the following reduce exposure in the meantime, based on the conditions documented in the GHSA advisory:
- Block or remove
pearcmd.php. Most sites have no legitimate need to expose PEAR's command-line utility over the web. Deny web access to anypearcmd.phpfile reachable under your document root, or remove it if your hosting stack doesn't require it, and confirm PHP'sregister_argc_argvsetting is disabled unless something specific depends on it. - Add a web server or WAF rule blocking requests to front-end URLs where the
pagenameparameter contains path-traversal sequences (such as encoded../or double-encoded variants) combined with apage_idparameter. - Restrict file permissions so the web server user cannot write PHP files into upload or temp directories it doesn't need to write to, which limits what a successful file-inclusion attempt can actually execute.
- Check your active theme for any top-level directory starting with
page-; if one exists and isn't essential, renaming or removing it removes one of the two conditions required for the RCE chain. - Monitor for indicators of compromise, including unexpected PHP files in
/tmp,/var/tmp, uploads folders, or theme directories, and unusual outbound connections from your web server process.
None of these substitute for updating WordPress Core. They buy time, not safety, and should be treated as a stopgap measured in hours, not weeks.
What's next
Expect continued, broad scanning for unpatched WordPress installs over the coming weeks — critical, unauthenticated Core vulnerabilities with public patches historically stay attractive to mass-exploitation botnets for months after disclosure, since a meaningful fraction of the WordPress install base updates slowly. CISA's KEV listing raises the stakes specifically for federal agencies and their contractors, but the practical advice for every WordPress site owner is the same: update to a patched release now, verify the update actually applied, and treat any site you can't immediately patch as an active target until you do. This is far from the only WordPress-adjacent or CMS vulnerability to get the KEV/patch-now treatment this year — see Pandromeda's earlier coverage of another actively exploited critical flaw and our reporting on recent patch-now advisories for a sense of how quickly attackers move once a fix ships.
Frequently asked questions
See the FAQ section below for quick answers on scope, exploitation status, and what to do if you manage multiple sites.
Frequently asked questions
What is CVE-2026-87902?
CVE-2026-87902 is a critical, unauthenticated path-traversal vulnerability in WordPress Core's get_page_template() function. It lets an attacker make WordPress include a readable local PHP file from outside the active theme's directories, which under certain theme and server conditions can lead to remote code execution. WordPress rates it CVSS 9.2 (Critical) and fixed it in version 7.1.2, released September 22, 2026.
Is my WordPress site affected?
Any WordPress Core installation from version 4.7.0 through 7.1.1 is affected, regardless of theme or plugins, since the bug is in Core. Check your version under Dashboard > Updates in wp-admin; if it's older than the patched release for your branch (7.1.2, 7.0.6, 6.9.9, and so on back to 4.7.37), update immediately.
Is CVE-2026-87902 being actively exploited?
Yes. According to BleepingComputer's reporting, attackers began probing for the flaw within hours of the September 22, 2026 patch, and attack volume increased roughly tenfold the next day. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on 2026-09-25.
Does CVE-2026-87902 always lead to remote code execution?
Not automatically. Full RCE requires two additional conditions documented in WordPress's GHSA-7hp8-65ch-5whp advisory: an active theme with a top-level directory starting with the 'page-' prefix, and a reachable PHP entry point such as pearcmd.php with PHP's register_argc_argv setting enabled. Without full RCE, the flaw still allows unauthenticated local file inclusion, which is serious on its own.
How do I update to a patched WordPress version?
In wp-admin, go to Dashboard > Updates and apply the update, run 'wp core update' via WP-CLI, or download the patched release directly from wordpress.org/download/releases/. WordPress backported the fix to every supported branch back to 4.7.37, so you can update within your current branch without a risky major-version jump.
What should I do if I can't patch right away?
Block or remove any web-reachable pearcmd.php file, disable PHP's register_argc_argv setting, add a WAF rule blocking path-traversal sequences in the pagename parameter, restrict write permissions in upload/temp directories, and check whether your active theme has a 'page-' prefixed directory. These reduce risk temporarily but do not replace updating WordPress Core.
Sources
- WordPress.org — Version 7.1.2 release documentationwordpress.org
- WordPress security advisory GHSA-7hp8-65ch-5whp (GitHub)github.com
- CISA Known Exploited Vulnerabilities Catalogcisa.gov
- NVD — CVE-2026-87902 detailnvd.nist.gov
- BleepingComputer — Hackers start exploiting critical WordPress flaw for code executionbleepingcomputer.com
- SecurityAffairs — CISA adds WordPress flaw to its KEV catalogsecurityaffairs.com
Sana Qureshi runs the security and privacy desk. She reports on actively exploited vulnerabilities, vendor patches and data breaches, and covers the password managers, VPNs and authentication tools readers use to protect themselves. Her alerts cite vendor advisories, CISA and the CVE record directly.


.webp)