XT.PT WordPress → This story
Filed
Reporting
Prelo
Verified by Roger Morais
4 min · 645 words
News WordPress

WordPress 7.1.2 fixes CVE-2026-87902, a page-template bug exploited within three days

Code execution needs a theme with a page- directory and a usable PHP file on the server; the advisory names both, and both can be checked.

Filed29 Sep 2026, 06:25 UTC Length4 min · 645 words ReportingPrelo
WordPress

WordPress released 7.1.2 on Tuesday, September 22, with a one-line explanation of why: "This security release features a fix for a critical severity security vulnerability." The fix went out the same day on every branch still receiving security fixes, back to 4.7. Three days later, on September 25, CISA added the flaw, CVE-2026-87902, to its Known Exploited Vulnerabilities catalog.

What was fixed

The advisory (GHSA-7hp8-65ch-5whp) describes the bug in two sentences:

An unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable local .php file outside the active theme directories. If relevant pre-conditions for both the server environment and the active theme are met, this can lead to RCE.

WordPress security advisory GHSA-7hp8-65ch-5whp

It is filed as CWE-98, PHP file inclusion. WordPress scores it 9.2 under CVSS 4.0, with the vector field AT:P: attack requirements present. CISA's own CVSS 3.1 score in the CVE record is 8.1, with high attack complexity. Both reflect the same point: the include itself needs no login, but code execution depends on what is on the box.

The affected range is every release from 4.7.0 through 7.1.1. Fixed versions include 7.1.2, 7.0.6, 6.9.9, 6.8.10, 6.7.9 and 6.6.9, and the advisory lists a patched point release for each branch down to 4.7.37. The release post adds a caveat for anyone relying on backports: "only the most recent version of WordPress is actively supported."

The two preconditions

The advisory names both conditions for code execution, and each is something an administrator can check.

The theme. "The active child or parent theme contains a top-level directory whose name starts with page- (e.g. page-templates)." The advisory says this covers the legacy Twenty Twelve and Twenty Fourteen themes, "as well as some popular third party themes such as Neve, Hestia, and Sydney."

The server. A usable PHP file has to exist and be readable by the web server account. The advisory names PEAR's pearcmd.php as the well-known route "when register_argc_argv is set to On," and says two common setups qualify: "The official php image for Docker is affected, and the default cPanel configuration is affected when PHP prior to 8.5 is in use."

Exploited within days

CISA's catalog entry, added September 25, set a due date of September 28 for federal civilian agencies and marks forensic triage as required. CISA's SSVC assessment in the CVE record reads: exploitation "active," automatable "no," technical impact "total." The "no" on automation fits the preconditions: a scanner cannot know in advance whether a given site's theme and PHP configuration line up.

The timestamps are tight. The GitHub advisory was published at 13:57 UTC on September 22 and the CVE record at 16:44 UTC. CISA does not say when exploitation began.

What to do

  • Update. The release post notes that sites with automatic background updates will update on their own. Anything pinned, containerized or managed by hand needs a check.
  • Check the theme (parent and child) for a top-level directory beginning with page-. A site without one does not meet the advisory's first condition, though the file inclusion itself is still fixed only by the update.
  • Check PHP. Our reading of the advisory, not its instruction: setting register_argc_argv to Off for web requests and keeping PEAR off web-served PHP installs removes the specific path it names. It does not close the bug.
  • Look back. CISA requires federal agencies to run forensic triage on this one. A site that ran a vulnerable version with a page- directory after September 22 deserves the same look: unfamiliar admin users, new PHP files, changed theme files.

Primary sources: WordPress 7.1.2 Release, GHSA-7hp8-65ch-5whp, CVE-2026-87902 record, CISA KEV alert, September 25, CISA KEV catalog, read 2026-09-29.

Corrections and source documents: contact the desk
Read next →
Read next
Edge devices · 4 min

NetScaler 14.1-73.37 fixes eight CVEs, and the exploited CVE-2026-88771 needs no special configuration

Supply chain · 5 min

Plugin4Shell: the commit Claude Code pinned was not always the one it installed