WordPress Core Path Traversal Flaw Remains Under Active Scanning a Week After Disclosure (CVE-2026-87902)
Scope: WordPress Core, All Versions Prior to 7.1.2 (Fix Backported to 4.7)
Severity: Red
CVE-2026-87902, the critical unauthenticated path traversal vulnerability WordPress patched in version 7.1.2 on September 22, 2026, remains an active exploitation risk more than a week after disclosure. Security researcher Robert Ressl originally discovered the flaw, which allows an unauthenticated attacker to manipulate WordPress's page template resolution to include a chosen readable PHP file from outside the active theme directory, and under specific server and theme conditions this can escalate into full remote code execution. WordPress security firm Patchstack recorded exploitation traffic increasing tenfold within days of the patch's release, with attackers moving from simple reconnaissance to actually writing files to disk, including payloads that plant a marker string confirming a host is exploitable for later, more damaging follow-up activity. Because WordPress powers a substantial share of websites across Uganda's government, education, and business sectors, any site that has not yet updated should be treated as likely already scanned and potentially marked for future targeting rather than merely theoretically at risk. Organizations must update to WordPress 7.1.2 immediately if this has not already happened, and review server logs and the file system, particularly the /tmp/ directory, for unfamiliar files as evidence of prior scanning or exploitation success.
The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.