WordPress Core Path Traversal Flaw Moves From Patch to Active Payload Delivery Within Hours (CVE-2026-87902)
Scope: WordPress Core, All Versions Prior to 7.1.2 (Fix Backported to 4.7.37)
Severity: Red
WordPress security firm Patchstack recorded the first malicious requests targeting CVE-2026-87902 at 17:44 UTC on September 22, 2026, less than five hours after WordPress released the patch in version 7.1.2. What started as reconnaissance traffic against a small number of sites has since grown roughly tenfold, with attackers now actively writing files to disk that execute shell commands when accessed, rather than simply probing for vulnerable installations. The flaw is an unauthenticated path traversal issue that lets get_page_template() resolve to and include an attacker-chosen readable PHP file from outside the site's active theme directories, which under certain server and theme conditions can be escalated into full remote code execution. Because WordPress enables automatic background updates by default, security researchers expect a high volume of exploitation attempts against sites that have not yet updated, even though the preconditions needed for a full compromise reduce how many of those attempts actually succeed. Given WordPress's dominant share of websites across Uganda's government, education, and business sectors, any site still on a version older than 7.1.2 should be treated as actively targeted rather than merely at risk. Organizations must update to WordPress 7.1.2 immediately if this has not already been done, and review the file system for unfamiliar PHP files located outside the site's active theme folders as an indicator of prior compromise.
The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.