WordPress CVE-2026-87902: Unauthenticated Path Traversal Under Active Attack
CVE-2026-87902 lets an unauthenticated attacker make WordPress 4.7.0 through 7.1.1 include a PHP file outside the theme folder, and on some servers that becomes remote code execution. Update to 7.1.2 or your branch's backport now; it's being exploited.
What is CVE-2026-87902?
CVE-2026-87902 is an unauthenticated path traversal bug in WordPress core. The function get_page_template() builds a template filename partly from the request, and it didn’t properly handle encoded ../ sequences. An attacker can steer it to any readable .php file on the server outside the active theme directories, and WordPress runs it.
The CVE record classes it as CWE-98 (PHP file inclusion). The WordPress advisory scores it 9.2 on CVSS v4; the CVE record’s CVSS v3.1 score is 8.1, with attack complexity marked high because code execution depends on server setup.
Which versions are affected?
Every WordPress release from 4.7.0 through 7.1.1. WordPress fixed it in 7.1.2 on September 22, 2026, and backported the fix to 24 older branches, including 7.0.6, 6.9.9, 6.8.10, and 4.7.37. If you’re on an older branch, the latest point release on that branch is patched.
Sites with automatic background updates enabled should already have it. Check the version under Dashboard → Updates anyway.
When does it become remote code execution?
Including a random PHP file is bad; running attacker code is worse. The chain Patchstack observed needs two things on the server:
- The active theme has a top-level
page-directory. - PHP has
register_argc_argvenabled, which hands the query string to included scripts as command-line arguments.
With both, attackers include PEAR’s pearcmd.php and pass it config-create arguments, which writes a PHP file of their choosing to disk. From there it’s a web shell.
How are attackers exploiting it?
Patchstack saw the first probe at 11:49 UTC on September 22, the same day the patch shipped. The attacks run in three stages:
- Check the bug is there. Requests with
pagenameholding encoded traversal (%2e%2eor double-encoded%252e%252e) pointing at harmless core files likewp-links-opml.phporwp-includes/feed-rss2.php. - Find PEAR. The same trick aimed at
pearcmdwith+config-show, trying/usr/local/lib/php/,/usr/share/php/, and/usr/share/pear/. - Write a file.
pearcmdwith+config-create, a PHP payload, and a path in/tmp.
A public Nuclei template landed on September 23, and traffic went up more than tenfold from the first evening. CISA added the CVE to its Known Exploited Vulnerabilities catalog on September 25.
How do I check whether my site was hit?
Search your web server access logs for:
- A
pagenameparameter containing%2e%2eor%252e%252e. pagenameandpage_idtogether in requests to the site root.pearcmd,+config-show, or+config-createanywhere in the URL.- User agents
cve-2026-87902-poc/1.0ornuclei-cve-2026-87902/1.0.
grep -Ei 'pagename=[^& ]*(%2e%2e|%252e%252e)|pearcmd|config-(show|create)|cve-2026-87902' /var/log/nginx/access.log*Then look for PHP files that shouldn’t exist, especially in /tmp and /var/tmp. Names seen so far include wp-pear-rce-flag.php and poc87902.php.
find /tmp /var/tmp -name '*.php' -newermt 2026-09-22 -lsProbes against core files only prove someone scanned you. A config-create request that returned 200, or a new PHP file on disk, means treat the server as compromised: take it offline, rotate credentials and salts, and rebuild from a known-good backup.
What if I can't update right now?
Update. If something truly blocks it for a few hours:
- Set
register_argc_argv = Offin php.ini and reload PHP-FPM. That breaks the pearcmd chain. - Block requests where
pagenamecontains..,%2e%2e, or%252e%252eat your WAF or reverse proxy.
Both reduce exposure. Neither fixes the bug.
Sources
- Sep 9CVE ID reserved.
- Sep 22WordPress 7.1.2 released, with fixes backported to every branch back to 4.7.
- Sep 22, 11:49 UTCFirst exploitation attempt seen by Patchstack, probing harmless core files.
- Sep 22, 15:34 UTCFirst file-write attempts through pearcmd.php.
- Sep 23Public Nuclei template released; attack traffic spikes.
- Sep 25CISA adds CVE-2026-87902 to the Known Exploited Vulnerabilities catalog.