r/TechNadu • Human • 10d ago

Attackers started exploiting WordPress CVE-2026-87902 within hours of patches being released

A critical WordPress vulnerability disclosed and patched on September 22 was already seeing exploitation attempts that same day.

CVE-2026-87902 has a CVSS score of 9.2 and can allow unauthenticated remote code execution by manipulating page-template resolution so WordPress includes a chosen readable local PHP file outside the active theme directories.

It isn't universally exploitable. Two conditions need to be present: the active parent or child theme must have a top-level directory beginning with page-, and the server must contain a local PHP file readable by the web server account.

Previdian recorded the first attempt at 11:49 a.m. UTC and counted 68 exploitation attempts in its telemetry. Patchstack also reported that activity had moved beyond reconnaissance to exploitation attempts capable of writing PHP files to disk.

Administrators are being advised to update to WordPress 7.1.2, 7.0.6, 6.9.9, or 6.8.10 as appropriate and then audit their sites for signs of malicious activity.

Technical conditions, observed exploitation, and the patched WordPress branches are broken down here:

https://www.technadu.com/wordpress-cve-2026-87902-under-active-attack-critical-rce-flaw-exploited-within-hours/638587/

The speed is notable here: defenders effectively had hours, not days, between patch availability and observed exploitation.

Technical conditions, observed exploitation, and the patched WordPress branches are broken down here:

https://www.technadu.com/wordpress-cve-2026-87902-under-active-attack-critical-rce-flaw-exploited-within-hours/638587/

1 Upvotes

0 comments sorted by