Close Menu
NCIJ Network NCIJ Network
    What's Hot

    A broken rib from the world’s largest T. rex hid a 66-million-year-old secret

    September 24, 2026

    As fires spread in Indonesia, Bornean orangutans run out of forest to flee

    September 24, 2026

    The west is in freefall – and the worst part is that we were warned, but chose not to listen | Owen Jones

    September 24, 2026
    Facebook X (Twitter) Instagram
    Trending
    • A broken rib from the world’s largest T. rex hid a 66-million-year-old secret
    • As fires spread in Indonesia, Bornean orangutans run out of forest to flee
    • The west is in freefall – and the worst part is that we were warned, but chose not to listen | Owen Jones
    • Benjamin Netanyahu to deliver defiant UN speech while facing protests and political isolation | Benjamin Netanyahu
    • Don’t believe the doomers: Europe’s tech industry slams AI panic – POLITICO
    • Labour likely to be biggest party in hung parliament, mega poll suggests – UK politics live | Politics
    • Meta’s next VR device isn’t a headset — it’s glasses
    • Critical WordPress Vulnerability Exploited Immediately After Disclosure
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, September 24
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Critical WordPress Vulnerability Exploited Immediately After Disclosure

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 24, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The exploitation of a fresh WordPress vulnerability started within hours of public disclosure and has escalated to active compromises, security firm Patchstack warns.

    Tracked as CVE-2026-87902 (CVSS score of 9.2), it is a path traversal flaw in WordPress’ page-template resolution. Under certain conditions, unauthenticated attackers could exploit it for remote code execution.

    “An unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable local .php file outside the active theme directories. If relevant pre-conditions for both the server environment and the active theme are met, this can lead to RCE,” WordPress’ advisory reads.

    The security defect can be triggered if the name of the top-level directory of the active child or parent theme starts with ‘page-‘ and if the web server account can read a chosen local .php target file that exists on the server.

    “The well-known pearcmd.php PEAR→RCE transition can be used for this when register_argc_argv is set to On. The official PHP image for Docker is affected, and the default cPanel configuration is affected when PHP prior to 8.5 is in use,” the advisory reads.

    Pearcmd.php provides a command-line tool for the management of PEAR packages in PHP environments and can be abused for RCE on servers with register_argc_argv enabled, especially when combined with a local file inclusion or a path traversal issue.

    Advertisement. Scroll to continue reading.

    According to WordPress, themes that contain the relevant directory layout include the legacy Twenty Twelve and Twenty Fourteen themes, along with third-party themes such as Neve, Hestia, and Sydney.

    The security defect was addressed on September 22 in WordPress version 7.1.2. The fix was also backported to previous WordPress releases, all the way back to 4.7.x.

    Within hours of public disclosure, Patchstack identified the first exploitation attempts targeting CVE-2026-87902.

    “The payloads match the exact encoding the patch addresses, so whoever built them was working from the diff rather than from an independent discovery,” the security firm notes.

    Originating from a small cluster of IP addresses, the initial exploitation activity was designed for reconnaissance, but escalated to active compromises by September 23, Patchstack says.

    “Traffic against this CVE is now running at more than ten times the volume we saw on the first evening; it is reaching a far wider spread of sites, and the requests have moved through three clear stages,” the security firm notes.

    The attackers first verify whether the target server is vulnerable, then check for PEAR’s pearcmd.php inclusion, and finally abuse pearcmd.php to write PHP content to achieve RCE.

    Patchstack suggests that the activity surrounding CVE-2026-87902 is likely to increase, as public scanning tools exist.

    Related: WordPress Patches ‘Click2Shell’ Vulnerability

    Related: Adobe Patches Critical Flaws in Connect, AEM Forms

    Related: Chrome 154 Patches 108 Vulnerabilities

    Related: Arista Urges Immediate Patching of Exploited VCO Zero-Day

    critical Disclosure Exploited immediately Vulnerability WordPress
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Hackers start exploiting critical WordPress flaw for code execution

    Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape

    Anthropic and OpenAI Models Still Attempt Restricted Actions in Safety Tests

    545 Hackers Tested It First. Now XRanges for AI Scores Your Security Agent

    New RemControl Android banking malware targets users in Europe and Canada

    New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    A broken rib from the world’s largest T. rex hid a 66-million-year-old secret

    September 24, 2026

    As fires spread in Indonesia, Bornean orangutans run out of forest to flee

    September 24, 2026

    The west is in freefall – and the worst part is that we were warned, but chose not to listen | Owen Jones

    September 24, 2026

    Benjamin Netanyahu to deliver defiant UN speech while facing protests and political isolation | Benjamin Netanyahu

    September 24, 2026
    Latest Posts

    Ransom Cartel ransomware creator sentenced to 16 years in prison

    August 5, 2026

    Uber CEO brushes off reports of a Waymo break-up

    August 5, 2026

    Fauci Faces Contempt Vote. Here Are the Legal Issues Involved.

    August 6, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    A broken rib from the world’s largest T. rex hid a 66-million-year-old secret

    September 24, 2026

    As fires spread in Indonesia, Bornean orangutans run out of forest to flee

    September 24, 2026

    The west is in freefall – and the worst part is that we were warned, but chose not to listen | Owen Jones

    September 24, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.