{"id":3123,"date":"2026-09-24T12:00:41","date_gmt":"2026-09-24T12:00:41","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=3123"},"modified":"2026-09-24T12:00:41","modified_gmt":"2026-09-24T12:00:41","slug":"attackers-exploit-wordpress-cve-2026-87902-within-hours-of-disclosure","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=3123","title":{"rendered":"Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Sep 24, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Web Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEizoRcyQE1N3fGUKa2FY_q_T7EG_CyjTpMGGk1oFUF-XpBZa0zCA6V2yEuv3_Z1OrEjMmhbHdaVmo6NMrwb98U9VFGXDpRcItboVuZH7qc9QgPd5ZLDudfJPWoaSDbtkoXJeLTZw-6JDbq5F6YEp4AkeoJd10Nb_H9tuU0fYdgqkLrP6BTpAPOYwO6WdmkN\/s1700-nu-rw-lo-l85-e365\/wordpress-exploits.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure.<\/p>\n<p>The vulnerability in question is <strong><a href=\"https:\/\/github.com\/WordPress\/wordpress-develop\/security\/advisories\/GHSA-7hp8-65ch-5whp\" target=\"_blank\">CVE-2026-87902<\/a><\/strong> (CVSS score: 9.2), which could allow an unauthenticated attacker to obtain remote code execution (RCE).<\/p>\n<p>\u00abAn unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable local .php file outside the active theme directories,\u00bb WordPress said in an advisory released two days ago. \u00abIf relevant preconditions for both the server environment and the active theme are met, this can lead to RCE.\u00bb<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/trust-world-update-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhYq3TvePXpW0JIC7fXyv7A1W8KQqmb-AZqza2EuPyT0k8Nm5CwHYHISFLKXSKIAyR8JRtqEFQ4zx5jADiAkZKQ08nRWG1jCRV5YAbhKua7WaDdH1L6wsI-xOkoV4brlMfK44UwU-4Q1xqWg0uNN7sZkMCzci4RXYgWMNPHTtuKua7OR4oCbmxE10u0yKnR\/s728-nu-rw-lo-l85-e365\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>Successful exploitation hinges on meeting the two pre-requisites &#8211;<\/p>\n<ul>\n<li>The active child or parent theme contains a top-level directory whose name starts with page- (e.g., page-templates).<\/li>\n<li>A chosen local .php target file exists on the server and is readable by the web server account. (e.g., pearcmd.php).<\/li>\n<\/ul>\n<p>In a statement shared with The Hacker News, Previdian said it&#8217;s seeing exploitation attempts targeting CVE-2026-87902 against its honeypot network, with the malicious requests originating from an IP address (104.194.9[.]227) located in the U.S. state of New Jersey.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>These requests include the local PHP file \/usr\/local\/lib\/php\/pearcmd.php, writing a file to \/tmp\/, and then including a PHP upload script hosted on GitHub (\u00abraw.githubusercontent[.]com\/MrG3P5\/web-shell\/refs\/heads\/main\/uploader.php\u00bb).<\/p>\n<p>\u00abAlthough this is undoubtedly a serious vulnerability, certain preconditions make exploitation less likely,\u00bb Previdian&#8217;s founder and CEO Ryan Dewhurst said. \u00abBecause WordPress has auto-updates enabled by default, we&#8217;re likely to see mass-exploitation attempts, but relatively few actual compromises.\u00bb<\/p>\n<p>Telemetry data from Previdian has <a href=\"https:\/\/previdian.com\/CVE-2026-87902#telemetry\" target=\"_blank\">recorded<\/a> a total of 68 exploitation attempts starting September 23, 2026. Some of the efforts have also originated from an Indonesia-based IP address.<\/p>\n<p>WordPress security company Patchstack has also <a href=\"https:\/\/patchstack.com\/articles\/cve-2026-87902-attackers-started-probing-wordpress-sites-hours-after-the-patch\/\" target=\"_blank\">warned<\/a> that the malicious requests have expanded from reconnaissance against harmless core files to active exploitation in which attackers include \u00abpearcmd.php\u00bb and use it to write PHP files to disk, corroborating findings from Previdian.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-security-guide-b\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiXA4q3EC_2cN4xiJDYmo1tVcCX5KORpjgj8jSp3DntuUZH4f0zu1Ru8jUwzShrquIuOxPb6q9TxJJXGuj7rxDRsXRSD34thOrXdZ9tDITDEj3Ocp0Z6GwhGekRTMhMnFjJ8UA5iSkfSnmnZrFzY5cmUlbCNiTNDNVrZvyef-AR_RLqwITnqZNi6PjeZkPC\/s728-nu-rw-lo-l85-e365\/AI-eBook-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The first exploitation effort was recorded on September 22, 2026, at 11:49 a.m. UTC, the same day patches were shipped for the flaw. In addition, the activity involves arbitrary file writes with attacker-controlled PHP content in locations like \u00ab\/tmp\u00bb and \u00ab\/var\/tmp.\u00bb Observed file names include &#8211;<\/p>\n<ul>\n<li>wp-pear-rce-flag.php<\/li>\n<li>poc87902.php<\/li>\n<li>luci_<random>.php<\/random><\/li>\n<li>zeta_<random>.php<\/random><\/li>\n<\/ul>\n<p>Some of the IP addresses linked to the malicious attacks &#8211; <\/p>\n<ul>\n<li>43.250.53[.]42<\/li>\n<li>180.251.159[.]243<\/li>\n<li>195.178.110[.]247<\/li>\n<li>107.189.14[.]87<\/li>\n<li>45.61.184[.]170<\/li>\n<li>92.246.130[.]76<\/li>\n<\/ul>\n<p>In light of active exploitation, website administrators are advised to apply WordPress version 7.1.2 (or 7.0.6, 6.9.9, 6.8.10) as soon as possible and audit for signs of malicious activity.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Sep 24, 2026Vulnerability \/ Web Security Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure. The vulnerability in question is&hellip;<\/p>\n","protected":false},"author":1,"featured_media":3124,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[622,3529,799,120,582,1927],"class_list":["post-3123","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-attackers","tag-cve202687902","tag-disclosure","tag-exploit","tag-hours","tag-wordpress"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3123","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3123"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/3123\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/3124"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3123"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3123"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3123"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}