WordPress CVE-2026-87902
Exploited. Fixed in 7.1.2.
A flaw in how WordPress picks a page template can let an attacker with no login run code on the server, when two conditions are met. WordPress fixed it on September 22, 2026, and CISA listed it as exploited on September 25. If a site of yours runs WordPress, confirm it updated.
Published September 30, 2026 · Last updated October 1, 2026
By Ace-Host, Southfield, Michigan: hosting on our own network (AS22878) since 2003
What happened
On September 22, 2026, WordPress released 7.1.2, a security release fixing CVE-2026-87902. In the advisory's words, an unauthenticated attacker can make WordPress's page-template resolution include a chosen readable local .php file outside the active theme directories, and if the pre-conditions for both the server and the active theme are met, this can lead to remote code execution.
WordPress rates it Critical, CVSS 4.0 9.2 (vector AV:N/AC:L/AT:P/PR:N/UI:N): reachable over the network, no login, no user interaction, with "attack requirements present", meaning the conditions below. The CVE record also carries a CVSS 3.1 score of 8.1, High. The weakness is CWE-98. WordPress credits Robert Ressl with reporting it.
It is being exploited. CISA added it to its Known Exploited Vulnerabilities catalog on September 25, 2026. Patchstack, a WordPress security firm, reports blocking a first attempt at 11:49 UTC on September 22, the day of the release, and a first attempt to write a PHP file to the server at 15:34 UTC the same day.
Who is affected
Every WordPress version from 4.7.0 through 7.1.1 that has not reached its branch's fixed release. WordPress fixed 7.1 and backported the fix to every branch back to 4.7:
- 7.1.2 · 7.0.6 · 6.9.9 · 6.8.10
- Older branches: 6.7.9, 6.6.9, 6.5.12, 6.4.12, 6.3.12, 6.2.13, 6.1.14, 6.0.16, 5.9.18, 5.8.17, 5.7.19, 5.6.21, 5.5.22, 5.4.23, 5.3.25, 5.2.28, 5.1.26, 5.0.29, 4.9.33, 4.8.32, 4.7.37
To see a site's version, open Dashboard » Updates, or with WP-CLI, from the site's directory:
wp core version
A result of 7.1.1 is affected; 7.1.2 is fixed. Sites that allow automatic background updates should have updated themselves already; the version check tells you whether yours did.
The advisory names two conditions that must both hold for code execution:
- The theme. The active theme, or its parent, has a top-level directory whose name starts with
page-, such aspage-templates. The advisory names Twenty Twelve, Twenty Fourteen, Neve, Hestia, and Sydney. To look, from the site's directory:ls -d wp-content/themes/*/page-*/ - The server. A usable
.phpfile is readable by the web server. The advisory's example is PEAR'spearcmd.phpwith PHP'sregister_argc_argvset to On, and it says the default cPanel configuration is affected when PHP before 8.5 is in use, as is the official PHP image for Docker.
Both are needed for code execution, per the advisory. Neither check replaces the update.
What to do
Update WordPress. In the dashboard, go to Dashboard » Updates and click Update Now. With WP-CLI, from the site's directory, update and read the version back:
wp core update
wp core version
wp core update moves to the newest release. To stay on your current branch and take only its fixed release (6.9.8 to 6.9.9, say), use wp core update --minor instead.
If you cannot update right away: the advisory offers no workaround. And because exploitation started the day of the fix, a site that sat on an affected version after September 22 is worth checking, not only patching. CISA asks the agencies it directs to do forensic triage for this one. Patchstack reports attackers writing PHP files to /tmp and /var/tmp; as root, this lists any PHP files there, and each one is worth a look:
find /tmp /var/tmp -name '*.php' -ls
On our shared or reseller hosting you won't have root, so that check isn't yours to run. If a WordPress site in your account sat on an affected version after September 22, log in and open a ticket and ask a system administrator to look. One will answer, 24/7/365.
For the log patterns Patchstack has seen, read its write-up, linked below.
Sources
- WordPress, WordPress 7.1.2 Release, September 22, 2026. Fetched September 30, 2026.
- WordPress security advisory, GHSA-7hp8-65ch-5whp: Unauthenticated path traversal in page-template resolution leading to conditional RCE (affected and patched versions, pre-conditions, CVSS 4.0 9.2). Fetched September 30, 2026.
- CVE record, CVE-2026-87902 (CNA: HackerOne; CVSS 3.1 8.1; CWE-98). Fetched September 30, 2026.
- CISA, Known Exploited Vulnerabilities catalog entry for CVE-2026-87902, added September 25, 2026. Fetched September 30, 2026.
- Patchstack, CVE-2026-87902: attackers started probing WordPress sites hours after the patch. Fetched September 30, 2026.
- WP-CLI, wp core update and wp core version. Fetched September 30, 2026.
Running WordPress on a server of your own? Our setup guide builds one step by step.