Threat actors began exploiting a critical WordPress flaw, CVE-2026-87902, rated 9.2, within hours of its public disclosure. The bug lets an unauthenticated attacker make get_page_template() include a chosen readable local .php file outside the active theme directories, which can lead to remote code execution when server and theme preconditions are met. Exploitation requires the active child or parent theme to contain a top-level directory whose name starts with page-, and a readable local .php target such as pearcmd.php. Previdian reported honeypot exploitation attempts from a New Jersey IP that include /usr/local/lib/php/pearcmd.php, write a file to /tmp, then pull a PHP upload script from GitHub to plant a web shell.