Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure
- ID
- 28038
- Status
- summarized
- Published
- 24 Sep 2026, 1:36 PM
- Fetched
- 24 Sep 2026, 6:14 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/attackers-exploit-wordpress-cve-2026.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 6.5
- Created
- 24 Sep 2026, 6:15 PM
- Tags
- Audience
- developersvibe_codersstartup_founders
What happened
The Hacker News reports active exploitation of CVE-2026-87902, a CVSS 9.2 unauthenticated remote code execution flaw in WordPress disclosed with patches on Sept 22, 2026. The bug lets get_page_template() page-template resolution include a chosen readable local .php file outside the active theme directories, but only if the active parent/child theme has a top-level directory whose name starts with 'page-' and a readable target file such as pearcmd.php exists on the server. Previdian logged 68 exploitation attempts from Sept 23, first seen Sept 22 at 11:49 a.m. UTC, including requests using /usr/local/lib/php/pearcmd.php, writing to /tmp/, and pulling an uploader script from a GitHub raw URL, from an IP in New Jersey (104.194.9[.]227) and one Indonesia-based IP; Patchstack corroborated the shift from recon to active exploitation, and Previdian's Ryan Dewhurst said default WordPress auto-updates mean mass attempts but relatively few compromises.
Why it matters
If you or a client run WordPress, this is a decision about two specific checks, not a general 'patch everything' reminder: confirm the site is on the version patched on Sept 22, and inspect whether the active theme has a top-level directory named page-* plus any readable stray .php like pearcmd.php in paths such as /usr/local/lib/php/ — both preconditions must hold for RCE, so most sites are not exploitable even though scanners are already hitting them. Malaysian agencies and founders hosting many client WordPress sites should inventory themes against that page- prefix pattern before assuming the default auto-update covers them, since a custom theme can block the fix from being the whole story.
Discussion angle
Walk through the two preconditions live — does anyone's theme have a top-level page-* directory, and is pearcmd.php reachable? — then debate whether default auto-updates are a real mitigation or just turn a targeted exploit into noisy mass scanning.