Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure
Key Points:
- A critical WordPress vulnerability (CVE-2026-87902) with a CVSS score of 9.2 allows unauthenticated remote code execution by including a local PHP file outside active theme directories, contingent on specific theme and server conditions.
- Exploitation requires the active theme to have a directory starting with "page-" and a readable local PHP file on the server, such as pearcmd.php, which attackers use to write malicious PHP files and execute code.
- Security firms Previdian and Patchstack have observed active exploitation attempts since September 22, 2026, with attacks originating from multiple international IP addresses, including the U.S. and Indonesia.
- Despite the severity, WordPress's default auto-update feature may limit successful compromises, though mass exploitation attempts are ongoing, with telemetry recording at least 68 attempts in a short period.
- Website administrators are urged to immediately update to WordPress versions 7.1.2, 7.0.6, 6.9.9, or 6.8.10 and conduct thorough audits for signs of compromise to mitigate risks.