Skip to content
Critical WordPress Vulnerability Exploited Within Hours of Patch Release

Critical WordPress Vulnerability Exploited Within Hours of Patch Release

First seen 24 Sep 2026, 11:55 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 24, 2026 at 12:55 UTC
  • CVE-2026-87902 allows unauthenticated remote code execution in WordPress.
  • Exploitation began within hours of the patch release on September 22, 2026.
  • Affected themes include legacy Twenty Twelve and Twenty Fourteen, among others.

On September 22, 2026, WordPress released version 7.1.2 to address CVE-2026-87902, a critical path traversal vulnerability with a CVSS score of 9.2. This flaw allows unauthenticated attackers to execute remote code under specific conditions, primarily affecting versions 4.7.0 through 7.1.1. Within hours of the patch, security firm Patchstack confirmed active exploitation attempts, with attackers leveraging the vulnerability to gain unauthorized access. The attack method involves probing for specific PHP files and exploiting the pearcmd.php component when certain server configurations are met. Themes like Twenty Twelve and Twenty Fourteen are particularly vulnerable due to their directory structure. As of September 23, exploitation activity had escalated significantly, indicating a rapid increase in attempts across various sites. Administrators are urged to apply the patch immediately to mitigate risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-22
WordPress 7.1.2 released
WordPress addressed CVE-2026-87902, a critical vulnerability allowing remote code execution.
Linkedin
2026-09-22
First exploitation attempts detected
Patchstack reported initial exploitation attempts targeting the newly disclosed vulnerability within hours of its announcement.
Securityweek
2026-09-22
CVE-2026-87902 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-23
Escalation of exploitation activity
Exploitation traffic surged, reaching ten times the initial volume, indicating widespread attempts to compromise vulnerable sites.
Securityweek
2026-09-24
Patch urgency emphasized
Security experts stress the importance of applying the patch to prevent unauthorized access and exploitation.
Forkast.News

More articles in this cluster (3)

Following this threat?

Track CVE-2026-87902 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed