Opens in a new tab

WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers

  • Home
  • Blog
  • WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers
Glowing padlock securing a WordPress critical flaw on a server rack

Site owners can close a critical route to remote code execution by updating WordPress to the 7.1.2 release issued on September 22. The patch addresses a flaw rated critical with a CVSS score of 9.2, tracked as CVE-2026-87902, and it ships across every supported branch back to 4.7. Updating is the only fix, and the project is telling site owners to do it now.

The vulnerability lets an attacker with no account make a site load a PHP file from outside its theme folders. On servers that already hold a useful PHP file, that first step can turn into running code of the attacker’s choosing. Every version from 4.7.0 through 7.1.1 is affected, including 7.1.1 from the security release issued just five days earlier on September 17. This is a separate flaw from the one that release fixed.

Which WordPress version to update to

WordPress backported the fix to every older branch it still supports as a courtesy, down to 4.7.37. The target version depends on the branch a site runs:

  • 7.1.x updates to 7.1.2
  • 7.0.x updates to 7.0.6
  • 6.9.x updates to 6.9.9
  • 6.8.x updates to 6.8.10
  • 6.7.x updates to 6.7.9
  • 6.6.x updates to 6.6.9

Sites with automatic background updates enabled will start the update on their own. Everyone else can update from the dashboard under Updates or download the release from WordPress.org. There is no separate workaround.

How the flaw works

The weakness sits in how WordPress chooses the template file for a page. One of the file names it builds comes from part of the web address. On affected versions, WordPress did not run that value through its own check for ../ traversal steps, the same check that neighboring code already used. Because the name is built as page-{value}.php, a working attack needs two extra conditions.

First, the active theme must have a top-level folder whose name starts with page-. Second, the target file has to end in .php. Some themes, including older default WordPress themes, ship a folder that fits. The current default themes do not.

Loading a local PHP file runs whatever that file already does. Turning that into code the attacker controls requires a further condition: the server must already have a PHP file that does something useful when loaded. That is the “some servers” part of the description, and it is why the flaw does not mean full code execution on every affected site.

What shows how exposed a site is

Patchstack’s analysis points to two checks that reveal how close a site is to the worst case. The first is whether the active theme has a top-level folder whose name begins with page-. The second is whether PHP runs with the register_argc_argv setting turned on, since a known code-execution technique depends on it. Neither check is a fix, but both show the exposure level.

That register_argc_argv setting is off by default on PHP 8.5 and on by default on older PHP versions. Operators who cannot update immediately can reduce the route to code execution by turning the setting off for web requests and removing unused PEAR components. Neither step repairs the underlying flaw.

The demonstrated attack and current status

The researcher credited with finding the flaw disclosed it privately through WordPress’s HackerOne program in July and published a detailed write-up when the fix shipped, along with a proof-of-concept and a self-contained test lab. The demonstrated attack ran code with the privileges of the web-server account, not full control of the server, and it was tested against WordPress 7.0.2 in isolated local labs, not the patched release or any live site.

As of September 22, there were no reports of the flaw being used in attacks, and it had no entry in the U.S. CISA Known Exploited Vulnerabilities catalog.

FAQ

What is CVE-2026-87902 in WordPress?

CVE-2026-87902 is a critical flaw fixed in WordPress 7.1.2 that lets an unauthenticated attacker make a site load a PHP file from outside its theme folders. It is rated 9.2 on the CVSS scale and can lead to code execution on some servers.

Which WordPress versions are affected?

Every version from 4.7.0 through 7.1.1 is affected. The fix shipped on September 22 in WordPress 7.1.2, with backports to every supported branch down to 4.7.37.

How can I update my WordPress site?

Sites with automatic background updates enabled will update on their own. Otherwise, update from the dashboard under Updates or download the release from WordPress.org. There is no separate workaround; updating is the fix.


This article summarizes reporting from thehackernews.com.

← All Articles