Critical WordPress Vulnerability Exploited Immediately After Disclosure
The exploitation of a fresh WordPress vulnerability started within hours of public disclosure and has escalated to active compromises, security firm Patchstack warns.
Tracked as CVE-2026-87902 (CVSS score of 9.2), it is a path traversal flaw in WordPress’ page-template resolution. Under certain conditions, unauthenticated attackers could exploit it for remote code execution.
“An unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable local .php file outside the active theme directories. If relevant pre-conditions for both the server environment and the active theme are met, this can lead to RCE,” WordPress’ advisory reads.
The security defect can be triggered if the name of the top-level directory of the active child or parent theme starts with ‘page-‘ and if the web server account can read a chosen local .php target file that exists on the server.
“The well-known pearcmd.php PEAR→RCE transition can be used for this when register_argc_argv is set...
Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE