Download the latest Vulnerability & Exploitation Report

Download now
CVE-2026-87902 WordPress

CVE-2026-87902: 30,000 IPs Target WordPress in Five Days

WordPress Core Page-Template File Inclusion (CVE-2026-87902): 30,000 Addresses in Five Days, and the Patch Is Already on Your Site If Auto-Updates Did Their Job

CVE-2026-87902 is a CVSS 9.2 unauthenticated local file inclusion flaw in WordPress core 4.7.0 to 7.1.1 that can reach remote code execution on some servers. CrowdSec has observed 30,813 unique IP addresses sending matching requests since September 23, 2026. Confirm every site runs 7.1.2 or its branch’s fixed release today.

CVE-2026-87902

CVE-2026-87902 at a glance

  • Affected: WordPress core 4.7.0 to 7.1.1, on every supported branch
  • Fixed in: 7.1.2, 7.0.6, 6.9.9, 6.8.10 and backports down to 4.7.37 (September 22, 2026), advisory GHSA-7hp8-65ch-5whp
  • Vulnerability class: Path traversal into a PHP include (CWE-22, CWE-98)
  • Severity: CVSS 4.0: 9.2 Critical (WordPress advisory); CVSS 3.1: 8.1 High (CISA, used by the Live Exploit Tracker)
  • Authentication required: None
  • Public exploit: Yes. The researcher’s proof of concept and lab and a Nuclei template are public.
  • CISA KEV: Added September 25, 2026; federal deadline September 28, 2026 (today)
  • CrowdSec detection rule live since: September 23, 2026
  • First exploitation attempt observed: September 23, 2026 by CrowdSec; September 22 at 11:49 UTC per Patchstack
  • Exploitation phase: Rapid Escalation (since September 25, 2026)
  • Observation window used here: September 23 to September 27, 2026 (5 days) for signal counts. The unique-IP count comes from the Live Exploit Tracker as of September 28, 2026.

Key findings

  • Probing started the day the patch shipped: WordPress published the fix on September 22. Patchstack logged a first attempt at 11:49 UTC that same day, CrowdSec’s rule went live on September 23, and CISA listed the flaw on September 25. The window between “patch available” and “someone is testing your site” was measured in hours.
  • 322,680 signals in five days, and rising every day: Between September 23 and 27, the CrowdSec Network recorded 322,680 signals matching the CVE-2026-87902 pattern, 64,536 a day on average. Daily volume grew from 14,938 to 124,154 without a single down day.
  • The number of sources grew 100-fold: Distinct sources went from 237 on September 23 to 23,321 on September 27. Over the same days, signals per source fell from about 63 to about 5. A few noisy scanners have become a very large number of quiet ones.
  • RCE needs luck; the probe does not: The file inclusion works on any unpatched site. Turning it into code execution needs a theme folder named page-* and a PHP setup with PEAR and register_argc_argv enabled. Attackers are sending the whole chain anyway and checking which sites answer.

What is WordPress, and who is exposed to CVE-2026-87902?

WordPress runs a large share of the web’s company sites, blogs, shops, and landing pages. It is usually looked after by a marketing team, an agency, or a hosting provider, which is exactly why patch status is often nobody’s explicit job.

Why CVE-2026-87902 matters: Code execution on a WordPress server gives the attacker the database password in wp-config.php, the customer and user records, and a trusted domain to host phishing pages or card skimmers. Attackers observed by Patchstack and The Hacker News dropped web shell uploaders into /tmp/ after a successful chain.

CrowdSec CTI classifies 95% of the observed intent as infrastructure takeover. On the Live Exploit Tracker, 58% of targeted organizations are in commerce and 38% are small offices and home offices. Where the sector is known, hosting providers receive about 69% of signals. Germany accounts for 34% of targeted signals, France for 21% and Brazil for 11%. This describes where CrowdSec has visibility, not where WordPress is deployed.

How does CVE-2026-87902 work?

When WordPress resolves which template to use for a page, get_page_template() builds a filename from the pagename request parameter. Attackers send /?page_id=… with a pagename containing double URL-encoded ../ sequences. WordPress’s first sanitising pass sees harmless text; a later urldecode() turns it into a real path, and the resulting file is loaded with include. The root cause: this code path skipped the validate_file() check used elsewhere for the same kind of filename.

Including a PHP file is not the same as running the attacker’s code. The public chain includes PEAR’s pearcmd.php, which, when register_argc_argv is on, can be told to write a new PHP file. That setting is on by default in the official PHP Docker images and in cPanel environments below PHP 8.5, per Security Affairs. Twenty Twelve, Twenty Fourteen, Neve, Hestia and Sydney are among the themes the advisory lists as meeting the page-* folder condition.

These preconditions explain why CVE-2026-87902 carries two scores. WordPress rates it 9.2 Critical in CVSS 4.0, where the theme and server requirements count as “attack requirements” and complexity stays low. CISA rates it 8.1 High in CVSS 3.1, where the same requirements count as high attack complexity. Same flaw, two ways of scoring the conditions.

What is the CrowdSec Network observing for CVE-2026-87902?

Between September 23 and September 27, 2026, the CrowdSec Network recorded 322,680 signals from machines reporting requests that match the CVE-2026-87902 exploitation pattern, detected by the CrowdSec scenario released on September 23, 2026. That averages 64,536 signals per day, peaking at 124,154 on September 27 with 23,321 distinct sources. Between 1,288 and 1,987 CrowdSec machines reported it each day. The Live Exploit Tracker counts 30,813 unique IP addresses as of September 28.

By signal volume, sources come from the United States (22%), Iran (20%), Lithuania (8%), the Netherlands (7%), France (6%), and Bulgaria (5%). Iran’s share stands out; the same US-and-Iran mix opened the WP2Shell (CVE-2026-63030) wave in July.

The part worth flagging is the shape of the growth. Total signals rose eightfold, but distinct sources rose a hundredfold, while each address sent fewer requests. That is what it looks like when an exploit moves from a handful of researchers and early operators into commodity scanning tools spread across rented servers and compromised hosts. WP2Shell followed the same path and ended up the most-attacked flaw on the network (Week 35). CVE-2026-87902 got to 30,000 addresses in five days.

What this data does not show

  • A matching request is an exploitation attempt. CrowdSec cannot confirm any of them succeeded, and most targets will lack the theme or PHP conditions RCE needs.
  • 30,813 unique IP addresses are not 30,813 threat actors. One operator can rotate through thousands of cloud or proxy addresses.
  • These counts come from traffic reaching machines participating in the CrowdSec Network: a sample, not a census.
  • The scenario flags encoded traversal in pagename. It does not tell a harmless version check apart from a full PEAR write attempt.
  • Five days is a short window. The trend line should not be read as a forecast.

What defenders get wrong about CVE-2026-87902

The comfortable assumption is “WordPress auto-updates, so we’re done.” Security releases install automatically by default, which is why this will not be a mass-compromise event. The sites that get hit are the ones where someone switched auto-updates off: agency-managed sites pinned to a version, staging copies left online, containers built from an old image that never update themselves, and hosts where the filesystem is read-only. Containers built on the official PHP image are also where register_argc_argv is on by default. The exposure is concentrated precisely where nobody is looking.

The second mistake is to read “conditional RCE” as “low priority.” The condition check is what the attackers are automating. They do not need to know your theme in advance; they send the chain and see what comes back.

Where edge blocking has limits: a virtual patch stops the request pattern, but if a site was unpatched and vulnerable at any point since September 22, look for new PHP files in /tmp/, /var/tmp/, and wp-content/uploads/ before assuming it is clean.

How do you protect WordPress against CVE-2026-87902?

Patch: Upgrade to WordPress 7.1.2, or the fixed release of your branch (7.0.6, 6.9.9, 6.8.10, and so on down to 4.7.37), per GHSA-7hp8-65ch-5whp. Confirm with wp core version or under Dashboard → Updates, and check container images and staging copies, not just production.

Virtual patching with CrowdSec AppSec. Until every site is upgraded, the CrowdSec AppSec Component inspects HTTP requests before they reach WordPress and blocks those matching crowdsecurity/vpatch-CVE-2026-87902: encoded ../ sequences in the pagename parameter, in the URL or a form body.

Preemptive blocking: Subscribe to real-time updates on the Live Exploit Tracker page for CVE-2026-87902 to block the addresses behind this activity as they appear. With 23,000 new sources on a single day, a list only helps if it updates as fast as the scanners rotate; it will not catch a first-seen address. Query the observed sources in CrowdSec CTI.

Frequently asked questions about CVE-2026-87902

Is CVE-2026-87902 being exploited in the wild? Yes. Attempts began on September 22, 2026, the day of the fix. CrowdSec recorded 124,154 matching signals on September 27 alone, and CISA added it to KEV on September 25.

Which versions of WordPress are affected by CVE-2026-87902? WordPress 4.7.0 to 7.1.1. The first fixed releases are 7.1.2 and 7.0.6, with backports on every branch down to 4.7.37.

Can I mitigate CVE-2026-87902 without upgrading? Partly. Disabling register_argc_argv and removing pearcmd.php closes the known RCE route, and the CrowdSec virtual patch blocks the request pattern. The inclusion flaw stays until you upgrade.

Related CrowdSec threat alerts


Written and reviewed by Matthieu M., Data Team Lead, CrowdSec. Published September 28, 2026.

Sharing insights and acting quickly can collectively reduce the impact of these threats. This is your call to action for real-time threat intelligence and collaborative cybersecurity.

WRITTEN BY