Hackers are targeting a critical WordPress flaw, so be on your guard
WordPress Core flaw CVE‑2026‑87902 (path traversal, 8.1 severity) enables PHP file inclusion and possible RCE Patch released in v7.1.2 and backported to 4.7+; exploitation began within hours, now widespread Admins must urgently update; interim mitigations include blocking traversal sequences and disabling risky ARP/PHP settings Hackers are actively exploiting a high severity vulnerability in WordPress that can lead to full website takeover, researchers are saying.
A patch is available, and WordPress users are urged to upgrade immediately or risk losing access to their assets.
Discovered by security researcher Robert Ressl, the vulnerability in question is tracked as CVE-2026-87902.
It is an 8.1/10 (high severity) unauthenticated path traversal flaw affecting WordPress Core.
According to WordPress itself, as well as the National Vulnerability Database, the bug can lead to local PHP file inclusion and, in certain scenarios, remote code execution (RCE).
"An unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable local .php file outside the active theme directories," it was said in the official security advisory.
Achieving RCE WordPress is the world’s number one website hosting and builder platform , powering more than half of all websites active on the internet right now.
However, that doesn’t mean all of them are susceptible to RCE.
Only websites ticking these boxes are at risk: Sites with parent or child themes that have a top-level directory with a name starting with ‘page-’ (for example, ‘page-templates).
Threat actors must target a local .PHP file that exists and is readable by the web server The web server account must be able to read the included file (for example, pearcmd.php, if PHP’s register_argc_argv setting is active) WordPress said that both the official PHP image for Docker, and the default cPanel configuration, are affected (users must be running a PHP version before 8.5, though).
The issue was fixed in version 7.1.2, which is now available for download.
Fixes were also backported to older versions up to 4.7.
Releases before 4.8 are not supported, it was said, and will not be getting a fix.
Attacking vulnerable websites Wordpress security company Patchstack said the first exploitation attempts started roughly five hours after the patch was released, and these were primarily reconnaissance efforts.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.techradar.com — the content belongs to TechRadar.