Attackers have started actively exploiting a critical security vulnerability in WordPress shortly after details of the flaw were publicly disclosed. Identified as CVE-2026-87902, the vulnerability carries a CVSS severity score of 9.2 and could allow unauthenticated attackers to achieve remote code execution under specific conditions. Security researchers have observed exploitation attempts targeting WordPress websites, raising concerns among administrators about the need for timely patching and security reviews. WordPress has released fixes for the issue and advised users to update affected installations to reduce potential risks.
According to WordPress security guidance, the vulnerability exists within the handling of page template resolution through the get_page_template() function. Under certain server and theme configurations, an unauthenticated attacker could cause the function to include a selected readable local PHP file outside the active theme directories. If the required conditions are met, the issue could potentially allow remote code execution on the affected website. Successful exploitation depends on multiple factors, including whether the active parent or child theme contains a top level directory beginning with “page” and whether a targeted local PHP file exists on the server and can be accessed by the web server account. Security experts noted that these conditions may limit widespread compromise, but the severity of the vulnerability makes immediate updates important.
Cybersecurity company Previdian reported that it has detected exploitation attempts targeting CVE-2026-87902 through its honeypot network. According to the company, some malicious requests originated from an IP address linked to New Jersey, United States, and attempted to include the local PHP file /usr/local/lib/php/pearcmd.php. The activity reportedly involved writing files to temporary directories and attempting to include a PHP upload script hosted on GitHub. Previdian Founder and CEO Ryan Dewhurst stated that while the vulnerability is serious, the required conditions for successful exploitation may reduce the number of confirmed compromises. The company added that WordPress automatic updates being enabled by default could help limit the impact by allowing many installations to receive security fixes more quickly.
Telemetry data from Previdian recorded 68 exploitation attempts beginning September 23, 2026, with some activity also linked to an Indonesia based IP address. Security firm Patchstack has also reported that malicious activity progressed from initial reconnaissance attempts involving harmless core files to more active exploitation attempts. Researchers observed attackers using pearcmd.php to write PHP files to server locations, including temporary directories such as /tmp and /var/tmp. Files identified during these activities included names such as wp-pear-rce-flag.php, poc87902.php, and randomly generated PHP filenames. Additional IP addresses associated with observed activity included 43.250.53[.]42, 180.251.159[.]243, 195.178.110[.]247, 107.189.14[.]87, 45.61.184[.]170, and 92.246.130[.]76.
The first reported exploitation attempt was recorded on September 22, 2026, at 11:49 a.m. UTC, on the same day security updates for the vulnerability were released. Security researchers have advised website administrators to install updated WordPress versions, including 7.1.2, 7.0.6, 6.9.9, or 6.8.10, depending on their current installation branch. Organizations are also encouraged to review website activity logs, monitor for unauthorized file changes, and investigate signs of malicious activity following the disclosure. The rapid exploitation of CVE-2026-87902 highlights the importance of maintaining updated content management systems and applying security patches quickly as attackers increasingly target publicly disclosed vulnerabilities.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.





