WordPress 7.1.2 patches CVE-2026-87902 exploited within hours
WordPress 7.1.2 shipped on 22 September 2026 to fix a remote file inclusion flaw, CVE-2026-87902, in get_page_template(). Exploitation attempts began the same day, with Previdian honeypots logging 68 tries, and the fix was back-ported to branches as old as 4.7.
- CVE-2026-87902 lets an unauthenticated attacker include local PHP files outside the active theme
- Exploitation needs a page-* directory in the theme and a readable pearcmd.php with register_argc_argv enabled
- Previdian honeypots recorded 68 exploitation attempts, the first from New Jersey on patch day
- The fix was back-ported to 4.7.37, 6.7.9, 6.8.10, 6.9.9 and 7.0.6
Read next
Security