Skip to content

WordPress 7.1.2 patches a critical RCE already under attack

An unauthenticated local file inclusion in template resolution reaches every version back to 4.7. Attackers started probing within hours of the patch.

Source: WordPress.org

WordPress shipped 7.1.2 on 22 September, patching a critical, unauthenticated remote code execution flaw in how the platform resolves page templates.

The bug, CVE-2026-87902, lets an attacker manipulate template resolution into including a readable local PHP file from outside the active theme’s directory — no login required. It affects every version from 4.7.0 through 7.1.1, and WordPress backported the fix all the way down to 7.0.6, 6.9.9, 6.8.10 and 4.7.37, so there’s a patched release for whichever branch you’re on.

Why it matters: this isn’t a theoretical risk. Patchstack recorded scanning traffic against the flaw starting at 11:49 UTC the same day the patch shipped — reconnaissance first, then probes for pearcmd.php, then attempts to write PHP files to disk. If you run WordPress and haven’t updated yet, do it now rather than at the next maintenance window.

The caveat: auto-updates only cover this if minor updates are enabled on your install, and some managed hosts lag by a day or two. Check your version number directly instead of assuming the host has handled it.

Share

Related reading

More from The Wire

All briefs