Hackers exploited a critical WordPress flaw within hours of the patch

Attackers began exploiting a critical WordPress flaw within hours of the fix. The bug, CVE-2026-87902, can let an attacker with no login run code on a website’s server. It only works under certain conditions.

WordPress fixed the flaw in version 7.1.2 on 22 September. It also patched every older branch back to 4.7. Its security advisory rates it critical, with a CVSS score of 9.2, and credits Robert Ressl with reporting it. The first attacks came at 11:49 UTC that day, according to WordPress security company Patchstack.

How the attack works

The flaw sits in get_page_template(), the function that picks which template file shows a page. An unauthenticated attacker can make it load a readable PHP file from outside the active theme’s folders.

Two conditions have to be met. The active theme must contain a top-level folder whose name starts with “page-”. The server must also hold a PHP file the attacker can use. In the attacks so far, that file is pearcmd.php, part of the PHP package manager PEAR.

After probing WordPress core files, attackers checked for pearcmd.php in three common locations, Patchstack said. They then used it to write files into the server’s /tmp and /var/tmp folders. Traffic then climbed steadily, Patchstack’s research lead Dave Jong wrote. It peaked around midday UTC on 23 September at more than ten times the volume of the first evening.

Auto-updates limit the damage

Security company Previdian recorded 68 exploitation attempts, The Hacker News reported. Its founder and chief executive, Ryan Dewhurst, said the conditions make a break-in less likely.

“Because WordPress has auto-updates enabled by default, we’re likely to see mass-exploitation attempts, but relatively few actual compromises,” Dewhurst told The Hacker News.

Site owners should update to 7.1.2 or the patched release on their branch. Patchstack also advises blocking “..” sequences in the pagename parameter. Turning off PHP’s register_argc_argv setting breaks the pearcmd step.

A month of exploited flaws

The WordPress bug is the latest in a run of flaws exploited soon after disclosure. Cisco warned this month that hackers were exploiting a maximum-severity ISE flaw. Microsoft’s September update fixed a record 974 flaws, two of them already under attack. Google patched a Chrome V8 flaw used in attacks.

Published

Back to top

Original source Hackers exploited a critical WordPress flaw within hours of the patch

Back to home