Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: local-file-inclusion (1 article)Clear

Attackers exploit unauthenticated WordPress code execution flaw within hours of its disclosure

Threat actors began exploiting a critical WordPress flaw, CVE-2026-87902, rated 9.2, within hours of its public disclosure. The bug lets an unauthenticated attacker make get_page_template() include a chosen readable local .php file outside the active theme directories, which can lead to remote code execution when server and theme preconditions are met. Exploitation requires the active child or parent theme to contain a top-level directory whose name starts with page-, and a readable local .php target such as pearcmd.php. Previdian reported honeypot exploitation attempts from a New Jersey IP that include /usr/local/lib/php/pearcmd.php, write a file to /tmp, then pull a PHP upload script from GitHub to plant a web shell.

Check
Update WordPress to the patched release now, then check whether active themes contain page- prefixed directories and review web logs for pearcmd.php requests.
Affected
WordPress sites meeting the theme and server preconditions let an unauthenticated attacker chain local file inclusion into remote code execution, already seen in the wild.
Fix
Apply the WordPress patch, harden PHP to disable pearcmd.php inclusion, and block the observed exploit indicators at the web tier.