WordPress CVE-2026-87902: Critical RCE Flaw Exploited, Patch Now

WordPress 7.1.2 fixes a critical, unauthenticated path-traversal bug in get_page_template() that attackers began exploiting within hours of disclosure. CISA has ordered federal agencies to patch fast.

The official WordPress logotype
The WordPress logotype. Image: WordPress.

WordPress has shipped an emergency fix, and site owners need to act now. On September 22, 2026, the WordPress security team released version 7.1.2 to patch CVE-2026-87902, a critical, unauthenticated path-traversal vulnerability in WordPress Core's template-resolution code that can lead to remote code execution. The bug has existed since WordPress 4.7 in 2016, attackers were probing for it within hours of the patch going out, and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added it to its Known Exploited Vulnerabilities (KEV) catalog. If you run WordPress and haven't updated in the last week, treat this as urgent.

CVE ID: CVE-2026-87902
Severity: Critical — CVSS v4.0 base score 9.2 (Vector: AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
Vulnerability type: Unauthenticated path traversal / local file inclusion in get_page_template(), potentially leading to remote code execution
Affected versions: WordPress Core 4.7 through 7.1.1 (all branches back to 4.7.0)
Patched versions: 7.1.2 (current), with backports to 7.0.6, 6.9.9, 6.8.10, 6.7.9, 6.6.9, 6.5.12, 6.4.12, 6.3.12, 6.2.13, 6.1.14, 6.0.16, 5.9.18, 5.8.17, 5.7.19, 5.6.21, 5.5.22, 5.4.23, 5.3.25, 5.2.28, 5.1.26, 5.0.29, 4.9.33, 4.8.32 and 4.7.37
Discovered/reported by: Security researcher Robert Ressl, via WordPress's HackerOne bug-bounty program
CISA KEV status: Added to the KEV catalog on 2026-09-25, with a remediation due date of 2026-09-28 for U.S. federal agencies

What happened

WordPress's security team disclosed and patched CVE-2026-87902 on September 22, 2026, as part of the WordPress 7.1.2 security release. According to WordPress's own release documentation, "this release features one security fix," described as "an unauthenticated path traversal issue in page-template resolution leading to conditional remote code execution," credited to researcher Robert Ressl. The advisory was also published by the WordPress security team as GHSA-7hp8-65ch-5whp on the wordpress-develop GitHub repository, which lists the flaw as critical with a CVSS v4.0 score of 9.2.

What makes this release unusual is its reach. WordPress doesn't just patch the current 7.1 branch for a critical, unauthenticated bug — it backports fixes to every legacy branch still receiving security support. In this case that meant simultaneous point releases across 23 separate version branches, all the way back to WordPress 4.7.37, closing a hole that had sat in WordPress Core's codebase for nearly a decade.

What CVE-2026-87902 actually is

The vulnerability lives in get_page_template(), the WordPress Core function responsible for resolving which template file to load for a given page. Per the GHSA advisory, an unauthenticated attacker can manipulate the pagename parameter — together with a valid page_id — using double-encoded path-traversal sequences so that WordPress's template-resolution logic includes a readable local .php file that sits outside the active theme's directories. Because the function runs unauthenticated, on the front end, no login or account of any kind is required to trigger it.

On its own, tricking WordPress into including an arbitrary local PHP file is a serious information-disclosure and file-inclusion bug. Whether it escalates to full remote code execution depends on two additional, independently documented conditions:

  • Theme structure: the site's active theme must contain a top-level directory whose name starts with the prefix page- (for example, a page-templates folder). Several popular themes, including older WordPress defaults and a number of third-party themes, use this convention.
  • A reachable, writable PHP entry point: the server needs some other readable .php file the attacker can leverage. Researchers demonstrated a practical chain using pearcmd.php — a command-line utility bundled with PHP's PEAR package manager — when the PHP register_argc_argv setting is enabled. That combination lets an attacker swap PEAR's config-show argument for config-create, which pearcmd.php will use to write an attacker-controlled PHP file to disk, which the traversal bug then executes.

pearcmd.php ships in the official PHP Docker images and is present by default in many common cPanel PHP configurations, which is why security researchers have flagged this as a realistic, not theoretical, RCE path on a meaningful slice of the WordPress hosting base.

Who is affected

Every WordPress Core installation from version 4.7.0 up to and including 7.1.1 is affected, regardless of which plugins or themes are installed, since the vulnerable code sits in Core itself. WordPress powers a large share of all websites, and this bug has been present in every release for almost ten years, so the exposed population is large by default — actual exploitability on any given site still depends on the theme and server conditions described above, but the flaw is trivially reachable and requires no authentication, which is why WordPress treated it as critical for the entire install base rather than a narrow edge case.

BranchAffected versionsPatched version
7.17.1.0 – 7.1.17.1.2
7.0up to 7.0.57.0.6
6.9up to 6.9.86.9.9
6.8up to 6.8.96.8.10
6.7up to 6.7.86.7.9
6.6up to 6.6.86.6.9
6.5up to 6.5.116.5.12
6.4up to 6.4.116.4.12
6.3up to 6.3.116.3.12
6.2up to 6.2.126.2.13
6.1up to 6.1.136.1.14
6.0up to 6.0.156.0.16
5.9up to 5.9.175.9.18
5.8up to 5.8.165.8.17
5.7up to 5.7.185.7.19
5.6up to 5.6.205.6.21
5.5up to 5.5.215.5.22
5.4up to 5.4.225.4.23
5.3up to 5.3.245.3.25
5.2up to 5.2.275.2.28
5.1up to 5.1.255.1.26
5.0up to 5.0.285.0.29
4.9up to 4.9.324.9.33
4.8up to 4.8.314.8.32
4.7up to 4.7.364.7.37

Sites still running WordPress 4.6 or earlier receive no fix — those branches are past end-of-life for security support and should be upgraded to a current, supported release rather than patched in place.

Active exploitation: what attackers are doing

This is not a theoretical bug sitting quietly in a disclosure report. According to BleepingComputer's reporting, malicious requests targeting the flaw began arriving within hours of the September 22 patch, and attack traffic increased roughly tenfold by the following day as opportunistic scanning gave way to actual payload delivery. Attackers have been observed abusing the pearcmd.php chain described above to write small PHP web shells to temporary directories such as /tmp and /var/tmp, with file names like wp-pear-rce-flag.php or randomized names, which then let them execute arbitrary commands on compromised hosts.

The pattern is a familiar one for critical, unauthenticated WordPress Core bugs: the public release of a patch effectively hands reverse-engineers a roadmap to the vulnerable code, and mass scanning for unpatched sites typically follows within a day or two. Multiple independent outlets, including SecurityAffairs, have since confirmed that exploitation is ongoing and that CISA responded by fast-tracking the flaw into its KEV catalog.

CISA's Known Exploited Vulnerabilities listing

CISA added CVE-2026-87902 to its Known Exploited Vulnerabilities catalog on 2026-09-25, listing "WordPress" as the vendor and "Core" as the product, and describing it as a "WordPress Core Remote File Inclusion Vulnerability." The KEV entry sets a remediation due date of 2026-09-28 for U.S. federal civilian agencies under Binding Operational Directive 26-04, which governs prioritizing security updates based on risk. A KEV listing doesn't legally bind private organizations, but CISA's standing guidance is that any organization running an affected product should treat a KEV entry as a signal to patch on an equivalently urgent timeline — in this case, a matter of days, not weeks. You can also check the CVE's National Vulnerability Database entry for the CVSS scoring detail and CPE ranges.

Timeline

DateEvent
September 22, 2026WordPress releases version 7.1.2 (and 23 backported branch releases) patching CVE-2026-87902
September 22, 2026 (same day)First exploitation attempts observed in the wild, according to BleepingComputer
September 23, 2026Attack volume increases roughly tenfold as scanning shifts to payload delivery
September 25, 2026CISA adds CVE-2026-87902 to its Known Exploited Vulnerabilities catalog
September 28, 2026CISA's remediation due date for U.S. federal civilian agencies

How to check if your site is vulnerable

Start with the version number: log into wp-admin and check the WordPress version shown on the Dashboard, or under Dashboard > Updates. If it's earlier than the patched release for your branch (see the table above), your site is vulnerable to CVE-2026-87902 regardless of which theme or plugins you run, since the flaw lives in WordPress Core's /wp-includes/template.php file. WordPress's own changelog for the 7.1.2 release confirms that file as the only one revised to fix this issue, so if you have any doubt, you can compare its contents against a known-patched copy of WordPress Core.

If you manage many sites, a managed WordPress host or security plugin that reports Core version numbers across your fleet will get you an answer faster than checking each dashboard individually. Hosts that auto-apply minor Core security releases — as most reputable managed WordPress hosts do — should already be patched, but it's worth confirming rather than assuming, especially on self-managed VPS or dedicated-server installs.

How to patch

The fix is a standard WordPress Core update, and most sites can apply it in minutes:

  • In wp-admin, go to Dashboard > Updates and apply the update if one is offered, or update to the latest version in your branch (7.1.2, or the corresponding patched release for your branch listed above).
  • If automatic background updates for minor/security releases are enabled (the WordPress default for point releases), many sites will already have received 7.1.2 automatically — check your version to confirm.
  • Sites managed via WP-CLI can run wp core update, or update to a specific patched version with wp core update --version=7.1.2.
  • You can also download the patched package directly from the WordPress.org releases page and apply it manually if you manage updates outside the dashboard.
  • After updating, verify the version number shown in wp-admin matches the patched release for your branch.

There's no reason to jump multiple major versions just to get this fix — WordPress backported it all the way to 4.7.37 specifically so sites on older, still-supported branches don't have to do a risky major-version migration under time pressure. Update within your current branch first; consider a broader upgrade plan separately, on your own schedule.

If you can't patch immediately: mitigations

Patching is the only fix that closes the vulnerability itself, and it should happen as soon as possible. If a full Core update genuinely cannot happen right away — for example, on a heavily customized site that needs regression testing first — the following reduce exposure in the meantime, based on the conditions documented in the GHSA advisory:

  • Block or remove pearcmd.php. Most sites have no legitimate need to expose PEAR's command-line utility over the web. Deny web access to any pearcmd.php file reachable under your document root, or remove it if your hosting stack doesn't require it, and confirm PHP's register_argc_argv setting is disabled unless something specific depends on it.
  • Add a web server or WAF rule blocking requests to front-end URLs where the pagename parameter contains path-traversal sequences (such as encoded ../ or double-encoded variants) combined with a page_id parameter.
  • Restrict file permissions so the web server user cannot write PHP files into upload or temp directories it doesn't need to write to, which limits what a successful file-inclusion attempt can actually execute.
  • Check your active theme for any top-level directory starting with page-; if one exists and isn't essential, renaming or removing it removes one of the two conditions required for the RCE chain.
  • Monitor for indicators of compromise, including unexpected PHP files in /tmp, /var/tmp, uploads folders, or theme directories, and unusual outbound connections from your web server process.

None of these substitute for updating WordPress Core. They buy time, not safety, and should be treated as a stopgap measured in hours, not weeks.

What's next

Expect continued, broad scanning for unpatched WordPress installs over the coming weeks — critical, unauthenticated Core vulnerabilities with public patches historically stay attractive to mass-exploitation botnets for months after disclosure, since a meaningful fraction of the WordPress install base updates slowly. CISA's KEV listing raises the stakes specifically for federal agencies and their contractors, but the practical advice for every WordPress site owner is the same: update to a patched release now, verify the update actually applied, and treat any site you can't immediately patch as an active target until you do. This is far from the only WordPress-adjacent or CMS vulnerability to get the KEV/patch-now treatment this year — see Pandromeda's earlier coverage of another actively exploited critical flaw and our reporting on recent patch-now advisories for a sense of how quickly attackers move once a fix ships.

Frequently asked questions

See the FAQ section below for quick answers on scope, exploitation status, and what to do if you manage multiple sites.

Frequently asked questions

What is CVE-2026-87902?

CVE-2026-87902 is a critical, unauthenticated path-traversal vulnerability in WordPress Core's get_page_template() function. It lets an attacker make WordPress include a readable local PHP file from outside the active theme's directories, which under certain theme and server conditions can lead to remote code execution. WordPress rates it CVSS 9.2 (Critical) and fixed it in version 7.1.2, released September 22, 2026.

Is my WordPress site affected?

Any WordPress Core installation from version 4.7.0 through 7.1.1 is affected, regardless of theme or plugins, since the bug is in Core. Check your version under Dashboard > Updates in wp-admin; if it's older than the patched release for your branch (7.1.2, 7.0.6, 6.9.9, and so on back to 4.7.37), update immediately.

Is CVE-2026-87902 being actively exploited?

Yes. According to BleepingComputer's reporting, attackers began probing for the flaw within hours of the September 22, 2026 patch, and attack volume increased roughly tenfold the next day. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on 2026-09-25.

Does CVE-2026-87902 always lead to remote code execution?

Not automatically. Full RCE requires two additional conditions documented in WordPress's GHSA-7hp8-65ch-5whp advisory: an active theme with a top-level directory starting with the 'page-' prefix, and a reachable PHP entry point such as pearcmd.php with PHP's register_argc_argv setting enabled. Without full RCE, the flaw still allows unauthenticated local file inclusion, which is serious on its own.

How do I update to a patched WordPress version?

In wp-admin, go to Dashboard > Updates and apply the update, run 'wp core update' via WP-CLI, or download the patched release directly from wordpress.org/download/releases/. WordPress backported the fix to every supported branch back to 4.7.37, so you can update within your current branch without a risky major-version jump.

What should I do if I can't patch right away?

Block or remove any web-reachable pearcmd.php file, disable PHP's register_argc_argv setting, add a WAF rule blocking path-traversal sequences in the pagename parameter, restrict write permissions in upload/temp directories, and check whether your active theme has a 'page-' prefixed directory. These reduce risk temporarily but do not replace updating WordPress Core.

Sources

More on WordPress →WordPressCVE-2026-87902patch nowCISA KEVremote code executionWordPress security
Sana Qureshi
Written bySana Qureshi

Sana Qureshi runs the security and privacy desk. She reports on actively exploited vulnerabilities, vendor patches and data breaches, and covers the password managers, VPNs and authentication tools readers use to protect themselves. Her alerts cite vendor advisories, CISA and the CVE record directly.

More from Security & Privacy

See all