A critical security flaw in WordPress, tracked as CVE-2026-87902, has raised concerns among website administrators. The vulnerability, rated 8.1 out of 10 in severity, allows an unauthenticated attacker to exploit a path traversal flaw in the WordPress Core. This flaw enables the inclusion of arbitrary PHP files and, in some cases, remote code execution (RCE), which could allow attackers to take full control of a website. The issue has been patched in the latest WordPress version, 7.1.2, and fixes have also been backported to older versions up to 4.7. However, users running versions earlier than 4.8 are no longer supported and will not receive a patch.
According to the official security advisory, the vulnerability affects how WordPress resolves page templates using the get_page_template() function. An attacker could manipulate this process to include a local PHP file from outside the active theme directory, which could be used to execute malicious code. The flaw impacts users running WordPress with the official PHP Docker image or default cPanel configurations, provided they are using PHP versions before 8.5. This means a large number of websites could be at risk if they haven’t updated their software.
Exploitation attempts began almost immediately after the patch was released and have since grown widespread. Security firm Patchstack noted that initial attacks were reconnaissance efforts, but malicious activity has since escalated as attackers attempt to deliver payloads to vulnerable sites. Public scanning tools designed to detect this specific vulnerability are now circulating, making it easier for attackers to identify and target unpatched WordPress installations.
Attackers are now using a file called pearcmd.php to write PHP files to the server's disk, allowing them to execute arbitrary code. Initially, attacks came from a limited number of IP addresses, but the sources have now expanded to hundreds, making it impractical to block them individually. Some of the most active IP addresses observed include 43.250.53.42, 180.251.159.243, 195.178.110.247, 107.189.14.87, 45.61.184.170, and 92.246.130.76. For users who cannot update immediately, blocking traversal sequences in the pagename parameter can help prevent exploitation, as legitimate page slugs never include these sequences. Additionally, disabling register_argc_argv can prevent the pearcmd chain from being used, reducing the risk from an information leak to full code execution.
Critical WordPress Vulnerability Exploited for Remote Code Execution
AI-rewritten from original reportingHow it works
wordpresscve-2026-87902security-patchrcevulnerability



