WordPress has patched a critical vulnerability, CVE-2026-87902, that lets an attacker with no account on a site force it to load a PHP file from outside the theme folder, and on some server configurations that escalates to full code execution. The fix for this WordPress critical vulnerability shipped on 22 September in WordPress 7.1.2, backported to every branch the project still supports, back to version 4.7. That reach, covering release lines going back nine years, is the tell: the bug lives in WordPress core rather than a plugin or theme, so every unpatched install carries the same exposure regardless of age.
How the WordPress critical vulnerability works
CVE-2026-87902 is a file-inclusion bug. It lets an unauthenticated request tell WordPress to load and execute a PHP file that lives outside the theme directory it should be confined to. On a typical shared host that alone can expose site internals or feed a chain toward further compromise.
On servers where an attacker can also get a file onto disk, through a separate upload path, a writable temp directory, or a misconfigured filesystem, the same inclusion bug becomes full code execution: WordPress ends up running a file the attacker planted, with whatever privileges the web server process holds. That second step is why the advisory calls the impact server-dependent rather than universal, and why the fix went out to every supported branch rather than just the current one.
Exploitation is no longer theoretical
The gap between disclosure and attack was short. Threat actors scanning for CVE-2026-87902 have moved on to actively exploiting it, using the flaw to write files to disk that execute shell commands when accessed, BleepingComputer reports. That detail matters more than the flaw’s existence: a web shell dropped this way survives a WordPress update unless it is found and removed separately.
By our arithmetic, that shift happened fast: teqpost calculates roughly 24.5 hours separated the first report of the patch from the first confirmed report of exploitation in the wild. That is not much runway for a site owner running an affected branch to patch before the flaw was weaponised, and it argues against treating “we’ll update this weekend” as a safe plan for any internet-facing WordPress install.
This is a pattern teqpost has tracked through September: on 19 September we covered an unauthenticated RCE in Orkes Conductor already under active attack, on a similarly compressed timeline between disclosure and exploitation. CVE-2026-87902 repeats that timeline in software with a vastly larger installed base, which is what makes the short exploitation window here the more consequential story.
What to watch
- Any WordPress core install not yet on 7.1.2, or the equivalent patched point release for its branch back to 4.7, remains exposed.
- Managed-hosting customers should confirm the update actually applied rather than assume an automatic background update caught it.
- Self-hosted sites should check for PHP files that do not belong in the theme directory, the artefact BleepingComputer’s reporting points to as a sign of compromise, since a plain version update does not remove a shell already dropped on disk.








