Security Bulletin

WordPress CVE-2026-87902: Unauthenticated RCE Exploited Within Hours

4 min read Updated

WordPress patched CVE-2026-87902 on September 22, 2026. Attackers were exploiting it the same day. Within hours of disclosure, attackers progressed from reconnaissance to active exploitation attempts, including attempts to write malicious PHP files to disk.  

The vulnerability is critical, with a CVSS v4.0 score of 9.2. Unauthenticated attackers can exploit it remotely. A public scanning template is already in circulation, and CISA has added the vulnerability to its KEV catalog.  

The exploit moved faster than most patch cycles. Unpatched, internet-facing WordPress installations are under active attack. Successful exploitation still depends on the theme in use and specific server-side prerequisites. 

What Is CVE-2026-87902? Breaking Down the WordPress Core LFI-to-RCE Vulnerability 

Risk Analysis 

  • Severity: CRITICAL   
  • CVSS v4.0: 9.2 (CRITICAL ) 
  • Exploit available in public: Yes 
  • Exploit complexity: Moderate, depends on theme and server preconditions 
  • Affected Product: WordPress Core, get_page_template() page-template resolution 
  • Affected Versions: WordPress 4.7.0 to 7.1.1 

CVE-2026-87902 lets an unauthenticated attacker force get_page_template() to include a readable local .php file from outside the active theme directories. When specific server and theme conditions are met, that inclusion becomes remote code execution. 

Two preconditions decide whether a site is exploitable. The active parent or child theme must contain a top-level directory whose name starts with page-, such as page-templates. A target .php file must also exist on the server and be readable by the web server account. Attackers are using PEAR’s pearcmd.php as target. 

Successful exploitation enables: 

  • Inclusion of arbitrary local PHP files, confirming a site is vulnerable and exposing server behavior 
  • Under the required server conditions, attackers can use the pearcmd.php chain to write attacker-controlled PHP content to disk, resulting in code execution on the host. 
  • Delivery of web shells and uploader scripts, setting up persistent access or further compromise 

Root Cause: Unvalidated pagename in get_page_template() 

  • WordPress builds a list of candidate template filenames when it picks the file to render a page. One candidate comes directly from the pagename value in the URL with no proper validation. A few lines above, WordPress runs validate_file() on a different filename to block traversal. The pagename candidate never gets that check. 
  • WordPress does sanitize the slug first. That sanitizer rewrites literal dots and truncates at literal slashes, but it preserves escaped octets. A plain ../ payload fails. A percent-encoded one survives, and get_page_template() decodes it later. This is why every observed payload arrives encoded. 
  • The request also needs a valid page_id. Without one, WordPress returns a 404, and the vulnerable code never runs. 

Exploitation Flow: From Anonymous Request to Code Execution 

Patchstack tracked attack traffic move through three stages within a day: 

  • Stage one, confirm the inclusion – The attacker sends a crafted pagename with an encoded traversal and a valid page_id. The inclusion points at a harmless core file such as wp-links-opml.php or feed-rss2.php. The response tells the attacker whether the site is vulnerable. 
  • Stage two, confirm pearcmd – The inclusion targets pearcmd.php with config-show appended. If PHP runs with register_argc_argv enabled, the query string reaches pearcmd as $argv, confirming both PEAR and the argument trick work. Attackers try three common install paths across distributions and container images. 
  • Stage three, write the payload – The attacker swaps in config-create, which writes attacker-controlled PHP to a chosen path. Some payloads drop a marker string to build lists of vulnerable hosts. Others drop code that runs shell commands on access. 

Previdian’s honeypots saw the same chain end to end. Requests included pearcmd.php, wrote a file to /tmp/, and then pulled in a PHP uploader script hosted on GitHub. 

The first wave matched the exact encoding the patch fixes. Attackers were working straight from the patch diff. 

Affected WordPress Versions and Patch Status 

Detail  Versions 
Affected  WordPress 4.7.0 to 7.1.1 
Fixed in  Fixed: 7.1.2, 7.0.6, 6.9.9, 6.8.10, 6.7.9, 6.6.9, 6.5.12, 6.4.12, 6.3.12, 6.2.13, 6.1.14, 6.0.16, 5.9.18, 5.8.17, 5.7.19, 5.6.21, 5.5.22, 5.4.23, 5.3.25, 5.2.28, 5.1.26, 5.0.29, 4.9.33, 4.8.32, 4.7.37 
Backported fixes  All affected release branches down to WordPress 4.7.x 

Every affected branch has a patched release. Older sites can close the vulnerability without a major version jump. 

Sites with a top-level page- theme directory and register_argc_argv enabled face the full RCE path. Treat these as the highest priority. 

Mitigation and Remediation Steps for WordPress Site Owners 

The complete fix is upgrading WordPress Core. Auto-updates are on by default, but they can be disabled and hosting environments vary. Verify the installed version directly. 

  • Update immediately to WordPress 7.1.2, 7.0.6, 6.9.9, or 6.8.10, or the patched release on your branch. 
  • Block traversal sequences in pagename at the WAF or edge if you cannot update right away. Legitimate slugs never contain them, so normal traffic is unaffected. Cover both the query string and the POST body. 
  • Disable register_argc_argv in PHP as a stopgap. The inclusion vulnerability remains, but the pearcmd chain to code execution breaks. 
  • Audit logs for pagename values containing %2e%2e or %252e%252e, pagename and page_id together on the site root or /index.php, any request with pearcmd, +config-show, or +config-create, and the user agents cve-2026-87902-poc/1.0 and nuclei-cve-2026-87902/1.0. 
  • Check /tmp and /var/tmp for unexpected .php files such as wp-pear-rce-flag.php, poc87902.php, luci_<random>.php, and zeta_<random>.php. Their presence means a file write succeeded. Treat the host as compromised. 
  • Do not rely on IP blocklists. Attack traffic now comes from a few hundred addresses. 

AppTrana WAAP Coverage for CVE-2026-87902   

AppTrana customers are protected against exploitation attempts targeting CVE-2026-87902, including encoded path traversal in the pagename parameter and pearcmd.php inclusion attempts. 

Edge-level virtual patching blocks these payloads before they reach the application, across GET and POST requests and regardless of the WordPress version underneath. Teams get time to test and roll out the core update without open exposure in the interim. 

 AppTrana blocked this CVE-2026-87902 exploitation attempt, returning a 406 before the pearcmd payload could write a PHP file to the server. 

AppTrana blocked the CVE-2026-87902 exploitation attempt

Stay tuned for more relevant and interesting security articles. Follow Indusface on Facebook, Twitter, and LinkedIn.

Bhargavi Pallati

Bhargavi Pallati is a Security Researcher at Indusface with experience in threat analysis, web application security, and detection engineering. She has a strong background as a Security Analyst and has worked extensively on vulnerability assessment and coverage verification. Bhargavi focuses on analyzing emerging attack patterns, strengthening application-level defenses, and improving security controls through continuous research and learning.