
WordPress CVE-2026-87902 RCE exploited same day as patch via pearcmd.php file writes
CVE-2026-87902 saw active exploitation hours after disclosure, with 68 attempts using pearcmd.php to drop files in /tmp. Preconditions reduce blast radius yet do not prevent scanning. Patch immediately and audit for the listed artifacts.
The flaw allows get_page_template() to include arbitrary readable local PHP files when a theme directory starts with 'page-' and a target file such as pearcmd.php exists on disk. Exploitation chains this into arbitrary writes of attacker-controlled PHP in /tmp and /var/tmp, followed by inclusion of a GitHub-hosted uploader. Observed filenames include wp-pear-rce-flag.php, poc87902.php, luci_<random>.php and zeta_<random>.php.
Telemetry from Previdian and Patchstack shows requests from five IPs including 104.194.9.227 in New Jersey and 43.250.53.42, with the first attempt at 11:49 UTC on disclosure day. The activity expanded rapidly from reconnaissance to active file writes, confirming the advisory's precondition requirements while demonstrating that mass scanning occurs regardless.
WordPress ships auto-updates by default, yet the narrow theme and file prerequisites create an uneven risk surface that official statements understate. Contract and procurement records show similar path-traversal patterns in prior WordPress RCEs that were initially dismissed as low-likelihood until widespread compromise followed. Independent verification of the listed IPs against known scanning infrastructure remains absent from both vendor reports.
Administrators must immediately confirm version 7.1.2 or equivalent and scan for the listed temporary files plus any unauthorized GitHub inclusions. Continued monitoring of the five tracked IPs and new variants will reveal whether the current wave represents opportunistic scanning or targeted campaigns against specific hosting configurations.
Previdian: Attempts will surpass 300 within 10 days absent broader theme-file mitigations.
Sources (2)
- [1]Primary Source(https://wordpress.org/news/2026/09/security-release-712/)
- [2]Supporting Source(https://patchstack.com/articles/wordpress-cve-2026-87902-active-exploitation)