WordPress Patches Critical RCE in 7.1.2 as Attacks Hit Within 5 Hours
Updated
Updated · Computerworld · Sep 24
WordPress Patches Critical RCE in 7.1.2 as Attacks Hit Within 5 Hours
3 articles · Updated · Computerworld · Sep 24
Summary
WordPress 7.1.2 fixes CVE-2026-87902, a critical flaw that can let unauthenticated attackers execute code by forcing page template resolution to load a chosen local PHP file.
Patchstack said probing began in under five hours of the Sept. 22 release and exploitation followed the same day, with attack traffic rising roughly tenfold within a day.
Attackers are abusing pearcmd.php to write malicious PHP outside WordPress directories, then using the flaw to execute it—giving access to wp-config.php, credentials, admin creation and persistent backdoors.
The patch was backported to versions 4.7 through 7.1.1, widening the urgent update pool to nearly a decade of installs, including older enterprise deployments.
Security advisers said internet-facing WordPress systems now need hours-level, verified patching, while enterprises may stay exposed longer because change-control queues and forgotten microsites delay updates.