Categories Technology

Critical WordPress Flaw Is Under Active Attack — Update Now

Update Your WordPress Site Right Now

On September 22, 2026, WordPress released version 7.1.2, a security update fixing a critical vulnerability tracked as CVE-2026-87902. The flaw lets an unauthenticated attacker — someone with no login at all — force your WordPress installation to include an arbitrary readable PHP file from outside your theme’s directories. Under certain server and theme configurations, that escalates to remote code execution: the attacker runs their own code on your server.

WordPress scored it 9.2 out of 10 (critical). And here’s the part that should move you to act today rather than this weekend: attackers began probing for it within hours of the patch release. Security firm Patchstack detected the first exploitation attempts at 11:49 UTC on September 22 — the same day the fix shipped. It was added to the US CISA Known Exploited Vulnerabilities catalog on September 25.

If your site runs any WordPress version from 4.7.0 through 7.1.1, you are vulnerable. Update now.

What the Vulnerability Is

The flaw lives in get_page_template(), a core WordPress function in wp-includes/template.php that decides which theme template file should render a given page. WordPress builds a list of candidate template filenames, and one of those candidates is derived from the page name in the request URL without adequate validation.

An attacker crafts a URL that tricks WordPress into including a PHP file of their choosing from anywhere on the filesystem that the web server can read — outside the active theme directory. On its own, that enables reading configuration files and leaking credentials. But researchers found attackers going further: by abusing pearcmd.php, a component of the PHP package manager PEAR that may be present on PHP servers, they could write malicious files into the server’s /tmp and /var/tmp directories — turning file inclusion into full system compromise.

Two preconditions have to line up for the worst case: the active theme must contain a top-level directory starting with “page-“, and the server must have a readable PHP file the attacker can leverage. That narrows the blast radius, but with WordPress powering over 43% of all websites, “narrowed” still means a very large number of targets. Patchstack reported malicious traffic climbing through September 23, peaking at more than ten times the initial volume.

The vulnerability was discovered and reported by Robert Ressl, and WordPress credited him in the security release.

Which Versions Are Affected and Fixed

Your version Status What to do
7.1.x below 7.1.2 Vulnerable Update to 7.1.2 or newer
7.0.x Vulnerable Update to 7.0.6 or newer
6.9.x Vulnerable Update to 6.9.9 or newer
6.8.x Vulnerable Update to 6.8.10 or newer
Older, back to 4.7 Vulnerable Update to the latest security release of your branch (fixes go back to 4.7.37)

WordPress backported the fix to every branch still receiving security updates — 25 releases in total. You don’t have to jump to the newest major version to be safe; you just need the latest release in your branch.

One critical gotcha: if you updated to WordPress 7.1.1 earlier in September, you are still vulnerable. 7.1.1 falls inside the affected range. You need 7.1.2.

WordPress also reminds users that only the most recent version is actively supported. A backport patches this hole, but running an old branch remains a risk. Plan an upgrade to 7.1.x when you can.

How to Update Safely (Do This Now)

Step 1: Back Up First

Before touching anything, take a full backup — files and database. If your host offers one-click backups (most do, including Hostinger, SiteGround, and WP Engine), run one now. If not, use a backup plugin like UpdraftPlus. A backup takes five minutes and is the difference between a scare and a disaster if anything goes wrong.

Step 2: Update WordPress Core

  1. Log in to your WordPress dashboard.
  2. Go to Dashboard → Updates.
  3. You’ll see the new version available. Click Update to version 7.1.2 (or the patched release for your branch).
  4. Wait for the process to complete — don’t navigate away.

The update is a minor security release and is designed to apply cleanly. If your site uses automatic updates for minor releases (the default), you may already be patched — check anyway.

Step 3: Update Everything Else

While you’re in Dashboard → Updates, update your plugins and themes too. Attackers don’t limit themselves to one vulnerability, and outdated plugins remain the most common WordPress attack vector overall.

Step 4: Verify and Harden

  1. Go to Tools → Site Health and check for remaining issues.
  2. Confirm your version under Dashboard → Updates shows 7.1.2 or your branch’s patched release.
  3. If you were running a vulnerable version for any time after September 22, consider your site potentially probed. Look for unfamiliar admin users (Users → All Users), unknown files in your uploads directory, and unexpected scheduled tasks. A security plugin like Wordfence or Sucuri can scan for common indicators of compromise.
  4. Turn on automatic updates for minor releases if they aren’t already: Dashboard → Updates → “Enable automatic updates for all new versions of WordPress.”

Why This One Deserves Your Immediate Attention

Most WordPress vulnerabilities require an attacker to have at least a subscriber-level account, which limits mass exploitation. This one requires nothing — no login, no account, no interaction. That’s what puts it in the critical tier and what had attackers scanning within hours.

The pattern is also getting worse, not better. The window between disclosure and active exploitation keeps shrinking across the industry. The practical lesson: treat WordPress security releases as same-day tasks, not weekend tasks. Enable automatic minor updates so the next CVE-2026-87902 patches itself while you sleep.

Source: Kaspersky’s analysis of CVE-2026-87902. Version and patch details verified against WordPress’s GitHub security advisory (GHSA-7hp8-65ch-5whp). If anything here conflicts with WordPress.org’s current guidance, follow WordPress.org.

Related: How to Secure Your WordPress Site From Hackers (2026)

Related: How to Back Up a WordPress Website in 2026

Frequently Asked Questions

What is CVE-2026-87902?

CVE-2026-87902 is a critical unauthenticated path-traversal vulnerability in WordPress core’s get_page_template() function. It lets an attacker without any login force WordPress to include arbitrary readable PHP files, which can lead to remote code execution under certain server and theme configurations.

Which WordPress versions are affected?

All versions from 4.7.0 through 7.1.1. The fix landed in WordPress 7.1.2 (released September 22, 2026), with backports to all supported branches down to 4.7.37.

I’m on WordPress 7.1.1 — am I safe?

No. Version 7.1.1 is inside the affected range. Update to 7.1.2 or newer immediately.

Is CVE-2026-87902 being actively exploited?

Yes. Patchstack detected exploitation attempts within hours of the patch release on September 22, 2026, with attack volume peaking the next day. CISA added it to the Known Exploited Vulnerabilities catalog on September 25.

How do I update WordPress to 7.1.2?

Back up your site first, then go to Dashboard → Updates in wp-admin and apply the update. Update plugins and themes at the same time, then verify under Tools → Site Health.

What if my site was already hacked through this flaw?

Change all passwords (admin, hosting, database, FTP), restore from a clean backup made before September 22 if available, scan with a security plugin, remove unfamiliar admin users and files, and consider professional cleanup if you’re unsure. Then update everything.

Leave a Reply

Your email address will not be published. Required fields are marked *