WordPress 7.1.2 Released to Patch Critical Path Traversal Vulnerability (CVE-2026-87902)
September 23, 2026
WordPress released version 7.1.2 to fix a critical unauthenticated path traversal vulnerability (CVE-2026-87902) that could allow an attacker to load and execute a PHP file from outside the active theme folders.
Exploitation depends on specific conditions: a directory starting with page- under an active theme, existence of a readable local PHP file, and server settings such as PEAR and register_argc_argv enable remote code execution, otherwise writes to /tmp or /var/tmp and subsequent inclusion could lead to code execution.
The vulnerability stems from get_page_template() selecting templates using a filename derived from the URL pagename without proper validation, enabling directory traversal and potential RCE under certain server configurations.
Memorial efforts continue for Matt through projects at his station and Rainbow IPC, including fundraising, decals, and planned installations like memorial benches or bricks to honor his impact.
Detection and investigation guidance emphasize preserving logs (raw access and WAF logs), collecting metadata and hashes of /tmp and /var/tmp, and corroborating evidence across endpoints, servers, and related processes.
The subject volunteered with the Jefferson County Emergency Communications Squad, contributing to traffic control and security at major regional events, reflecting a broader commitment to public safety.
Anderson battled stage 4 colorectal cancer for seven years with tenacity, continuing to work and serve when possible, using blunt humor to describe his fight.
MITRE mapping links the issue to T1190 and T1059.004, with the note that confirmed code execution on individual hosts is not established from public telemetry alone.
Public exploit material exists, but there is no confirmed widespread attack as of the latest update; defenders should patch promptly and follow hardening guidance, including monitoring logs and restricting permissions.
On patch day, initial probing was blocked, but traffic surged by September 23, with patterns including pagename, encoded traversal, pearcmd, config-show, and config-create requests.
Public telemetry confirms probing and PHP write attempts, but full site compromise requires site-specific evidence beyond request logs.
SOC and admin guidance: verify WordPress core version, assess active themes and directories, monitor for PEAR-related probes, and coordinate containment if exploitation is suspected.
Summary based on 7 sources
Get a daily email with more Tech stories
Sources

Security Affairs • Sep 23, 2026
CVE-2026-87902: how close is your WordPress to remote code execution?
Help Net Security • Sep 23, 2026
WordPress 7.1.2 fixes critical unauthenticated path traversal vulnerability (CVE-2026-87902)