Technology reviews & practical guides
WordPress 7.1.2 fixes a CVSS 9.2 path-traversal bug in page-template resolution that dates back to 4.7. Attackers were probing within hours, and CISA's federal deadline is September 28.

WordPress shipped version 7.1.2 on September 22, 2026 to fix a single critical vulnerability, CVE-2026-87902, in the way WordPress core resolves page templates. The bug has been present in every release since WordPress 4.7.0, and the official advisory rates it Critical, with a CVSS 4.0 score of 9.2.
Attackers did not wait long. Patchstack logged the first exploitation attempt at 11:49 UTC on the day of the patch, and by September 23 activity had moved from probing to writing PHP files onto servers. CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 25, with a federal remediation deadline of tomorrow, September 28.
The flaw is serious but conditional: not every WordPress site can be taken over. Here is what was fixed, who is actually exposed, how to check your site and what to do if you cannot update today.
WordPress 7.1.2 is a security-only release. In the release post, John Blackbourn describes the issue this way: "An unauthenticated attacker can, under certain conditions, make page template resolution include a chosen readable local PHP file outside the active theme directories." Under certain server and theme conditions, that inclusion can lead to remote code execution.
The GitHub security advisory, GHSA-7hp8-65ch-5whp, is titled "Unauthenticated path traversal in page-template resolution leading to conditional RCE". It places the bug in get_page_template() and classifies it as CWE-98, improper control of the filename used in a PHP include or require statement. The CVSS 4.0 vector is AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N: network reachable, no login and no user interaction needed, but with attack prerequisites (AT:P) that must be present on the target.
The vulnerability was reported responsibly by Robert Ressl. Affected versions run from WordPress 4.7.0 through 7.1.1, and WordPress backported the fix to every branch from 4.7 onward.
WordPress 7.1.1, released earlier, fixed a different flaw: CVE-2026-93485, a stored XSS in comment rendering nicknamed Comment2Shell. CVE-2026-87902 is the page-template bug fixed in 7.1.2. A site on 7.1.1 is still exposed to it.
According to the advisory, two conditions have to line up. The first makes the file inclusion possible, and the second turns it into code execution.
That narrows the blast radius considerably. Previdian founder and CEO Ryan Dewhurst told The Hacker News: "Although this is undoubtedly a serious vulnerability, certain preconditions make exploitation less likely." WordPress also enables automatic background updates for minor and security releases by default, so many sites will have picked up the fix without anyone touching them.
The sites to worry about are the ones where auto-updates are turned off, pinned or blocked by the host, running one of the affected themes on a PHP stack that ships PEAR.
Patchstack, which deployed a virtual-patching rule the day the advisory went out, published a timeline of what its sensors saw. All times are UTC.
Patchstack describes three stages. Attackers first ran reconnaissance against ordinary files such as wp-links-opml.php, wp-includes/feed-rss2.php, wp-cron.php and wp-login.php. They then checked for pearcmd.php at /usr/local/lib/php/pearcmd.php, /usr/share/php/pearcmd.php and /usr/share/pear/pearcmd.php. Finally they switched pearcmd from config-show to config-create to write PHP files into /tmp and /var/tmp.
Patchstack, quoted by SecurityWeek, said: "The payloads match the exact encoding the patch addresses, so whoever built them was working from the diff rather than from an independent discovery." SecurityWeek reports that traffic rose more than tenfold by the second day and escalated to active compromises by September 23.
Other sensor networks see a smaller slice. As of September 27, Previdian's page for the CVE lists 407 exploitation attempts from 8 unique IP addresses in 7 countries, first observed on September 23 and last observed on September 26. These are counts from different observers, so they should not be added together.
CISA added CVE-2026-87902 to the Known Exploited Vulnerabilities catalog on September 25, 2026 as "WordPress Core Remote File Inclusion Vulnerability". The catalog entry sets a due date of September 28, 2026 for federal civilian agencies under Binding Operational Directive 26-04, "Prioritizing Security Updates Based on Risk", and flags the entry for forensic triage.
CISA lists known ransomware campaign use as "Unknown". The deadline only binds US federal agencies, but a KEV listing is a strong signal for everyone else that exploitation is real and ongoing.
The fix is to update. Go to Dashboard > Updates and click "Update Now", or download the release from WordPress.org. Sites with automatic background updates enabled will update on their own, but it is worth confirming the version number rather than assuming.
The fixed build depends on the branch a site runs. The patched versions are:
Patchstack's guidance is blunt: "Updating is still the answer, and given stage three it is now urgent." For sites that cannot update immediately, it recommends:
Patchstack lists these detection signals for access logs and file systems:
Updating closes the hole but does not remove anything an attacker already wrote. If a site ran an affected theme on a PEAR-enabled PHP stack and was unpatched after September 22, check /tmp and /var/tmp and review logs for the signals above.
More in Tech News
Browse Tech News