BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Critical WordPress RCE bug actively exploited within hours

Critical WordPress RCE flaw CVE-2026-87902 actively exploited; patch immediately to prevent compromise.

  • Threat actors are actively exploiting a critical WordPress vulnerability, CVE-2026-87902, just hours after its public disclosure.
  • The unauthenticated remote code execution (RCE) flaw carries a CVSS score of 9.2 and requires specific server and theme preconditions to be met.
  • Exploitation attempts, first recorded on September 22, 2026, include writing malicious PHP files to disk via the “pearcmd.php” local file.
  • Website administrators are urged to apply the patched WordPress versions immediately and audit for signs of compromise.

Threat actors have begun actively exploiting a critical security flaw in WordPress within hours of its public disclosure, targeting sites with an unauthenticated remote code execution (RCE) vulnerability. The flaw, tracked as CVE-2026-87902 (CVSS score: 9.2), allows an attacker to manipulate page-template resolution to include a chosen local PHP file, potentially leading to RCE.

- Advertisement -

According to WordPress’s advisory, successful exploitation hinges on two preconditions: the active theme must contain a top-level directory starting with “page-,” and a readable target PHP file must exist on the server. Previdian reported seeing exploitation attempts against its honeypot network, with malicious requests originating from a U.S.-based IP address in New Jersey.

These requests target the local PHP file /usr/local/lib/php/pearcmd.php to write a file to /tmp/, then include a PHP upload script hosted on GitHub. Telemetry data from Previdian recorded 68 exploitation attempts starting September 23, 2026, with additional activity from an Indonesia-based IP address.

Patchstack has also warned that malicious requests have expanded from reconnaissance to active exploitation, corroborating findings from Previdian. The first exploitation effort was recorded on September 22, 2026, at 11:49 a.m. UTC, the same day patches were shipped.

Consequently, website administrators are advised to apply WordPress version 7.1.2 (or 7.0.6, 6.9.9, 6.8.10) as soon as possible and audit for signs of malicious activity. Observed file names written by attackers include wp-pear-rce-flag.php and poc87902.php.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Micron stock target hiked to $1,300 by Citi as DRAM prices soar

Citi analyst Atif Malik raised the Micron stock price target to $1,300 from $1,150,...

Brooklyn man sentenced for $16M Coinbase phishing scam

Ronald Spektor, 23, sentenced to 4–12 years for stealing nearly $16 million from roughly...

OpenAI AI agent breaches Australian government Medicare site

An AI agent breached Australia's Medicare Statistics Reporting Service in June, accessing public and...

Claude AI discovers unknown enzyme system in viruses

Anthropic's AI model Claude spent 21 hours and roughly 210 million tokens searching DNA...

AI CEOs Urge UN Cooperation on Catastrophic Risks

OpenAI CEO Sam Altman and Anthropic CEO Dario Amodei urged the UN Security Council...

Must Read

The 10 Best Crypto Podcasts You Can’t Miss

Table of ContentsBest Cryptocurrency Podcasts To Add To Your Playing List1. The Money Movement2. The Crypto Conversation3. The Pomp Podcast4. What Bitcoin Did5. The...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading