Attackers Are Trying to Turn a WordPress Template Bug Into Code Execution
The patch window lasted hours. WordPress released fixes for a page-template flaw on 22 September, and Patchstack began seeing unauthenticated probes that same day. By 23 September, some requests were no longer checking whether the flaw existed. They were attempting to write attacker-controlled PHP files.
CVE-2026-87902 is an unauthenticated path-traversal weakness in WordPress Core’s page-template resolution. The WordPress advisory says it can make WordPress include a readable local PHP file outside the active theme directories. Under the right theme and server conditions, that inclusion can lead to remote code execution as the web-server account.
The exploit chain is conditional but the attack traffic is real
The distinction matters. The public research does not show that every default WordPress installation can be taken over. A vulnerable version is only the first requirement. The demonstrated chain also needs a published page, a suitable top-level theme directory such as page-templates, a readable local PHP target and filesystem rules that permit the include.
The demonstrated step from file inclusion to code execution adds further conditions. The research used a readable PEAR command entry point, register_argc_argv enabled for the web-facing PHP runtime and a writable destination. Those prerequisites limit the complete chain, but they do not repair the underlying inclusion flaw.
Patchstack says it first observed attempts at 11:49 UTC on 22 September. At 15:34 UTC, it recorded an attempt to use pearcmd.php to write a file. On 23 September, the company reported much higher volume, requests that reached the file-write stage and public scanning tooling identifying itself as a Nuclei template. Those observations establish attack traffic, but do not prove that a file write succeeded on every targeted site.
Every supported branch has a fixed release
WordPress fixed the 7.1 branch in 7.1.2 and backported the correction to older branches. Patchstack lists 7.0.6, 6.9.9 and 6.8.10 among the fixed builds, with backports extending to 4.7.37. Administrators should use the patched release for the branch they actually run, then verify the version served by every production node.
- Update WordPress Core immediately and verify the running version after deployment.
- Search access logs for
pagenamecombined withpage_id, encoded parent-directory sequences,pearcmd,config-showorconfig-create. - Inspect
/tmpand/var/tmpfor unexpected PHP files. Patchstack observed names includingwp-pear-rce-flag.php,poc87902.phpand randomisedluci_orzeta_files. - Treat a successful file write or unexpected PHP execution as compromise, not as a blocked scan.
- Review active parent and child themes for top-level directories beginning with
page-, but do not use their absence as a substitute for patching. - Disable
register_argc_argvfor web requests when it is unnecessary and remove unused web-readable PEAR components as defence in depth.
Blocking traversal sequences in the pagename parameter can reduce immediate exposure where an update cannot be installed at once. It remains a temporary control. A clean response from one probe also does not prove the underlying WordPress version is safe, because the complete result depends on local theme and runtime conditions.
The operational conclusion is narrow and urgent. CVE-2026-87902 is not universal one-request code execution across every WordPress site. It is a patched unauthenticated inclusion flaw with a public proof of concept, observed probing and attempts to turn the primitive into PHP execution. That is enough to make version verification and retrospective hunting a current incident-response task.
Sources
- WordPress security advisory GHSA-7hp8-65ch-5whp, published 22 September 2026. GitHub provides the date but no publication time.
- Robert Ressl’s technical disclosure and laboratory analysis, published 22 September 2026. No publication time is provided.
- Public proof of concept and reproducible local lab, released 22 September 2026.
- Patchstack exploitation observations, published 22 September and materially updated 23 September 2026. The page provides event times in UTC but no page publication clock.


