Updated
Updated · Computerworld · Sep 24
WordPress Patches Critical RCE in 7.1.2 as Attacks Hit Within 5 Hours
Updated
Updated · Computerworld · Sep 24

WordPress Patches Critical RCE in 7.1.2 as Attacks Hit Within 5 Hours

3 articles · Updated · Computerworld · Sep 24

Summary

  • WordPress 7.1.2 fixes CVE-2026-87902, a critical flaw that can let unauthenticated attackers execute code by forcing page template resolution to load a chosen local PHP file.
  • Patchstack said probing began in under five hours of the Sept. 22 release and exploitation followed the same day, with attack traffic rising roughly tenfold within a day.
  • Attackers are abusing pearcmd.php to write malicious PHP outside WordPress directories, then using the flaw to execute it—giving access to wp-config.php, credentials, admin creation and persistent backdoors.
  • The patch was backported to versions 4.7 through 7.1.1, widening the urgent update pool to nearly a decade of installs, including older enterprise deployments.
  • Security advisers said internet-facing WordPress systems now need hours-level, verified patching, while enterprises may stay exposed longer because change-control queues and forgotten microsites delay updates.

Insights

What makes a legitimate PHP package the perfect accomplice for hackers exploiting this critical WordPress vulnerability?
How does a hidden server setting turn a patched WordPress site into an attacker's playground within hours?