Cybersecurity

Attacks on WordPress RCE Flaw Rose Tenfold After Sept. 22 Fix

Published 2 min readBy NewUJ Editorial Desk

Updated new information added

Attacks on WordPress RCE Flaw Rose Tenfold After Sept. 22 Fix
Photo: WordPress.org
0 0
XWhatsAppTelegramLinkedIn

WordPress shipped version 7.1.2 on September 22, 2026 to close CVE-2026-87902, an unauthenticated path-traversal flaw in the core function that resolves page templates. Attackers moved on it the same day. WordPress security firm Patchstack told BleepingComputer it saw the first malicious requests at 17:44 UTC on September 22, coming from a small group of IP addresses aimed at sites it protects; The Hacker News reported that the first exploitation effort was recorded earlier that day, at 11:49 UTC.

The activity has escalated since. Patchstack said traffic tied to the bug rose tenfold on September 23 and shifted from reconnaissance — requests for ordinary WordPress core files, apparently to fingerprint vulnerable sites — to writing files to disk. Attackers abuse the PEAR utility pearcmd.php to drop attacker-controlled PHP into /tmp and /var/tmp, under names such as wp-pear-rce-flag.php and poc87902.php. Some payloads only mark a host as exploitable; others, Patchstack said, "write a short tag that executes a shell command on access." Security company Previdian told The Hacker News it had logged 68 exploitation attempts against its honeypot network starting September 23.

WordPress's security team rated the flaw critical at 9.2 out of 10, according to BleepingComputer; the entry in the US National Vulnerability Database carries a separate CVSS 3.1 score of 8.1, rated high. Exploitation is far from universal. The official advisory says the active theme or its parent must contain a top-level directory whose name begins with "page-" — it names the legacy Twenty Twelve and Twenty Fourteen themes, plus the third-party themes Neve, Hestia and Sydney — and a readable local .php file must exist on the server. The official PHP image for Docker is affected, as is the default cPanel configuration running PHP older than 8.5. "Because WordPress has auto-updates enabled by default, we're likely to see mass-exploitation attempts, but relatively few actual compromises," said Previdian founder and chief executive Ryan Dewhurst.

Neither firm has published a count of sites actually compromised; only attempts have been quantified. WordPress credited the discovery to researcher Robert Ressl and said the fix was backported to every branch still eligible for security updates, currently down to 4.7 — patched releases run from 7.1.2 and 7.0.6 through 6.9.9 and 6.8.10 and on to 4.7.37. BleepingComputer reports that releases before 4.6 will not receive a fix. Administrators are advised to update, review server logs for the file names above, and block the source addresses published by Patchstack.

Sources

Report / request removal

Related

Comments

No comments yet. Be the first.