Critical WordPress Flaw CVE-2026-87902 Exploited Within Hours of Patch Release
A critical path traversal vulnerability in WordPress core, tracked as CVE-2026-87902 with a CVSS v4.0 score of 9.2, was publicly patched on September 22, 2026. Security firm Patchstack observed unauthenticated attackers probing vulnerable sites and attempting PHP file writes on the same day the patch was released, with traffic volume surging tenfold by the following day. The flaw allows local file inclusion and can escalate to remote code execution in environments where specific theme directory structures, pearcmd.php, and certain PHP configurations are present. Successful exploitation requires several conditions to align, including the existence of a page- prefixed directory under an active theme and write permissions to target directories. WordPress site administrators are urged to update immediately to version 7.1.2 or the patched release for their active branch.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in