WordPress 7.1.2 Released to Patch Critical Path Traversal Vulnerability (CVE-2026-87902)

September 23, 2026
WordPress 7.1.2 Released to Patch Critical Path Traversal Vulnerability (CVE-2026-87902)
  • WordPress released version 7.1.2 to fix a critical unauthenticated path traversal vulnerability (CVE-2026-87902) that could allow an attacker to load and execute a PHP file from outside the active theme folders.

  • Exploitation depends on specific conditions: a directory starting with page- under an active theme, existence of a readable local PHP file, and server settings such as PEAR and register_argc_argv enable remote code execution, otherwise writes to /tmp or /var/tmp and subsequent inclusion could lead to code execution.

  • The vulnerability stems from get_page_template() selecting templates using a filename derived from the URL pagename without proper validation, enabling directory traversal and potential RCE under certain server configurations.

  • Memorial efforts continue for Matt through projects at his station and Rainbow IPC, including fundraising, decals, and planned installations like memorial benches or bricks to honor his impact.

  • Detection and investigation guidance emphasize preserving logs (raw access and WAF logs), collecting metadata and hashes of /tmp and /var/tmp, and corroborating evidence across endpoints, servers, and related processes.

  • The subject volunteered with the Jefferson County Emergency Communications Squad, contributing to traffic control and security at major regional events, reflecting a broader commitment to public safety.

  • Anderson battled stage 4 colorectal cancer for seven years with tenacity, continuing to work and serve when possible, using blunt humor to describe his fight.

  • MITRE mapping links the issue to T1190 and T1059.004, with the note that confirmed code execution on individual hosts is not established from public telemetry alone.

  • Public exploit material exists, but there is no confirmed widespread attack as of the latest update; defenders should patch promptly and follow hardening guidance, including monitoring logs and restricting permissions.

  • On patch day, initial probing was blocked, but traffic surged by September 23, with patterns including pagename, encoded traversal, pearcmd, config-show, and config-create requests.

  • Public telemetry confirms probing and PHP write attempts, but full site compromise requires site-specific evidence beyond request logs.

  • SOC and admin guidance: verify WordPress core version, assess active themes and directories, monitor for PEAR-related probes, and coordinate containment if exploitation is suspected.

Summary based on 7 sources


Get a daily email with more Tech stories

More Stories