SOCLYDE logo
Current languageEN
Cybersecurity newsVulnerabilityWordPressRCE

Wordpress: cve-2026-87902 exploited after the patch

A WordPress path-traversal flaw can lead to code execution under specific conditions. WordPress 7.1.2 and backported fixes are urgent.

By Soclyde Team

Hands checking a WordPress update and log checklist in a small-business office

In summary

  • CVE-2026-87902 can make WordPress include a readable local PHP file through page-template resolution under specific conditions.
  • WordPress 7.1.2 and backported fixes address the flaw; probes were followed by attempts to write executable files.
  • Patch, inspect logs and rotate secrets if the site was exposed during the relevant window.

Explore next

Soclyde resources

Article contents

On September 22, 2026, WordPress released 7.1.2 to fix CVE-2026-87902, a critical page-template resolution flaw. Early observations showed probing; researchers later reported exploitation attempts designed to write files and execute commands.

The risk is conditional: the chain requires a compatible theme and PHP environment. That nuance should not delay patching an exposed site, because an unauthenticated attacker can trigger the first step.

What WordPress fixed

The official advisory says an attacker can, under certain conditions, make WordPress include a readable local PHP file outside the active theme directories. When the server and theme prerequisites are present, that inclusion can lead to remote code execution.

The fix shipped in 7.1.2 and was backported to branches still receiving security updates. Check the installed version on every site, including staging copies.

Exploitation is accelerating

Patchstack observed malicious requests shortly after the release. BleepingComputer later reported increased traffic and attempts to write PHP files in temporary directories. This confirms exploitation activity, not compromise of every site.

An exposed site that still answers with a vulnerable version can be found by automated scanning. Perimeter controls do not replace updating core and the components that resolve pages.

Check the scope

Inventory WordPress, the parent or child theme and PHP settings. Review Docker images and cPanel configurations mentioned in reporting, then apply the fix for the maintained branch actually deployed.

Preserve logs before cleanup. Look for unusual page-template parameters, unexpected 200 responses, files added under /tmp or /var/tmp, new administrator accounts and edits to wp-config.php.

Accounts and secrets

If a credible attempt is found, investigate before deleting artifacts. Reset administrator accounts and rotate API keys, hosting access and passwords that the PHP process could have read.

Tell site administrators that urgent reset or payment requests may be follow-on phishing. Rotation should be coordinated with logs and the systems that use each secret.

The Soclyde connection

Soclyde does not patch WordPress or determine whether a site was compromised. It helps generate unique secrets, keep them in a local-first encrypted vault and identify access that needs rotation after the investigation.

That reduces copies in tickets, spreadsheets and chats. It does not replace WordPress patching, code review or incident response.

Key takeaways

CVE-2026-87902 is being actively exploited under specific conditions. Install WordPress 7.1.2 or the fix for your branch, inspect logs and rotate secrets when exposure is plausible. Read the secure password generator guide or contact Soclyde.

Frequently asked questions

Are all WordPress sites compromised?

No. Exploitation depends on the active theme, readable PHP files and PHP configuration. Every exposed vulnerable site should nevertheless be treated as a priority.

Which version should I install?

WordPress recommends 7.1.2, with fixes also backported to security-supported branches down to 4.7. Check the official advisory and your maintained branch.

What should be checked after patching?

Review requests involving template parameters, unexpected PHP files in /tmp or /var/tmp, new accounts, configuration edits and administrator sign-ins.

References

Sources and references

Need advice?

Design your password strategy with Soclyde

Schedule a dedicated walkthrough with the team to see how local-first security adapts to your stack.

Talk with us

Keep reading