deniz.in

Markets

Weather

Loading weather

· via dev.to (home feed)

WordPress 7.1.2 fixes critical path traversal to RCE flaw affecting versions back to 4.7

WordPress 7.1.2 patches an unauthenticated file inclusion flaw that can escalate to remote code execution, with fixes backported to 4.7 and CISA reporting active exploitation.

WordPress 7.1.2 fixes critical path traversal to RCE flaw affecting versions back to 4.7

Critical patch across every supported branch

WordPress has shipped version 7.1.2 to close a critical hole in core: an unauthenticated path traversal bug that, depending on server configuration, can be turned into remote code execution. According to a security write-up on dev.to, the issue is tracked as CVE-2026-87902 and GHSA-7hp8-65ch-5whp, carries a CVSS 4.0 score of 9.2, and affects every WordPress release from 4.7.0 through 7.1.1.

The release landed on 22 September 2026 alongside backports to every branch still eligible for security fixes — 7.0.6, 6.9.9, 6.8.10 and 6.7.9 among them, reaching back to 4.7.37. Sites that cannot move to the 7.1 line therefore still have a remediation path.

Exploitation is already underway

The dev.to post reports that CISA added CVE-2026-87902 to its Known Exploited Vulnerabilities catalog on 25 September 2026, three days after the patch shipped. Public scanning for vulnerable installs and attempts to write PHP files through pearcmd.php have reportedly already been observed in the wild.

A file inclusion bug in template resolution

The flaw sits in how WordPress resolves page templates. An unauthenticated request can steer get_page_template() into loading a readable local .php file located outside the active theme's directories. That makes it a local file inclusion issue, classed as CWE-98, rather than a generic escape from the web root: the attacker chooses which existing PHP file gets included rather than uploading a new one.

What it takes to reach code execution

Per the write-up, three conditions determine whether the inclusion escalates to execution:

  • The active theme, parent or child, has a top-level directory whose name starts with page-. This is not rare: page-templates/ ships with Twenty Twelve and Twenty Fourteen and appears in popular themes including Neve, Hestia and Sydney.
  • A readable .php file on the server that acts on arguments supplied by the attacker. In observed attacks, pearcmd.php is the target.
  • register_argc_argv is set to On in the PHP configuration. Official PHP Docker images qualify, as do default cPanel setups on PHP versions before 8.5.

The post warns that the conditional nature of the bug does not make it safe to skip: attackers probe for configurations that meet the requirements, and default shared hosting and VPS images are likely to qualify.

Patching and interim mitigations

The primary fix is updating core: wp core update via WP-CLI on server installs, or the one-click updater in hosting panels such as cPanel, Plesk or Kinsta. The post also recommends backing up files and the database first, confirming the installed version afterwards in the WordPress admin, and enabling automatic background updates for minor releases via WP_AUTO_UPDATE_CORE in wp-config.php.

If an immediate update is not possible, two configuration changes break the documented route from inclusion to execution: set register_argc_argv to Off and verify with php -i, then check whether a reachable pearcmd.php exists and remove it if nothing on the machine needs PEAR. Neither closes the underlying file inclusion, so patching remains the actual fix. A WAF such as Cloudflare, Wordfence or ModSecurity, and disabling file editing in the admin, are listed as general hardening. Notably, the post points out that blocking PHP execution in the uploads directory — standard advice for many WordPress bugs — does nothing against this CVE, since the attack relies on a file already present on disk.

Why it matters

WordPress powers an enormous share of the web, and this bug requires no credentials, no vulnerable plugin and no theme beyond what ships by default on many hosts. A CISA Known Exploited Vulnerabilities listing combined with observed scanning means opportunistic attacks are a matter of when, not if. Because patched releases exist for every supported branch down to 4.7, the practical takeaway is simple: update now, verify the version, and treat the register_argc_argv and pearcmd.php checks as a stopgap only.

  • #wordpress
  • #security
  • #vulnerability
  • #patching
  • #cms

Related posts