On 22 September 2026, WordPress released WordPress 7.1.2, a security update that fixes a critical vulnerability tracked as CVE-2026-87902. The flaw affects almost ten years of WordPress releases, from 4.7.0 through 7.1.1. Attackers began probing websites for it on the same day the patch was published.
The official WordPress announcement is clear: “it is recommended that you update your sites immediately.”
This WordPress 7.1.2 security update guide is part of our WordPress tutorials series. It explains, in plain language:
- what the vulnerability is
- which sites are at risk
- how to update safely (dashboard and WP-CLI)
- how to harden your server
- how to check whether your site was attacked before you patched
What Is CVE-2026-87902?
CVE-2026-87902 is an unauthenticated path traversal vulnerability in the way WordPress picks a page template. The official GitHub security advisory titles it “Unauthenticated path traversal in page-template resolution leading to conditional RCE.”
In simple terms, WordPress builds a template file name such as page-about.php from the page name in the request (the pagename query variable). The vulnerable code in get_page_template() (inside wp-includes/template.php) decodes this value without checking it properly. An attacker can sneak directory traversal sequences (../) into it. WordPress can then be tricked into loading a readable PHP file from outside the theme folder.
Loading an arbitrary local file is bad on its own. When certain server and theme conditions line up, it can become remote code execution (RCE), which means the attacker can run their own code on your server.
Quick Facts
| Detail | Information |
|---|---|
| CVE ID | CVE-2026-87902 (GHSA-7hp8-65ch-5whp) |
| Vulnerability type | Path traversal / local file inclusion (CWE-98) |
| Vulnerable function | get_page_template() in wp-includes/template.php |
| Login required? | No, unauthenticated |
| Severity | Critical, CVSS 4.0 score 9.2 |
| Affected versions | WordPress 4.7.0 to 7.1.1 |
| Fixed in | 7.1.2, plus backports to every branch down to 4.7.37 |
| Release date | 22 September 2026 |
| Reported by | Robert Ressl |
| Actively exploited? | Yes, from 22 September 2026 |
| CISA KEV | Added 25 September 2026 (KEV catalogue) |
Which Versions Are Fixed?
WordPress backported the fix to all branches eligible for security fixes (currently back to 4.7). You don’t have to jump to the latest major version to be safe. You only need the latest release in your branch:
| Your branch | Update to at least |
|---|---|
| 7.1.x | 7.1.2 |
| 7.0.x | 7.0.6 |
| 6.9.x | 6.9.9 |
| 6.8.x | 6.8.10 |
| Older branches | The latest security release of that branch (fixes go back to 4.7.37) |
Important: If you updated to WordPress 7.1.1 earlier this month, you are still vulnerable. 7.1.1 is inside the affected range, so you need 7.1.2.
WordPress also reminds users that “only the most recent version of WordPress is actively supported.” A backport patches this one hole, but running an old branch is still a risk. Plan an upgrade to 7.1.x.
Is Your Website Actually at Risk?
It helps to separate two things:
- The file inclusion bug exists on every site running 4.7.0 to 7.1.1.
- Remote code execution only happens when extra conditions are met.
According to Patchstack’s technical analysis, the known RCE chain needs all of the following:
- The active theme has a top-level folder whose name starts with
page-, for example apage-templatesfolder. Many themes keep their custom page templates in a folder named like this. - A readable PHP file that can be abused, such as PEAR’s
pearcmd.php, exists on the server. - PHP’s
register_argc_argvsetting is enabled. Patchstack notes that it’s on by default in official PHP Docker images and in cPanel environments running PHP versions below 8.5. The PHP manual lists its default value as on, and marks it as deprecated as of PHP 8.5.0 for non-command-line use.
Ryan Dewhurst, CEO of Previdian, told The Hacker News that the vulnerability is “undoubtedly a serious vulnerability”, but its preconditions make exploitation less likely.
Why Indian site owners should still act fast: A large number of small business, blog and WooCommerce sites in India run on cPanel-based shared hosting. That setup can match these conditions, and you often can’t see or change server settings yourself. If you’re planning to move to a server you control, read our comparison of cloud vs dedicated hosting. Agencies managing client sites can also see reseller hosting optimisations for WordPress. Whatever your setup, don’t try to work out whether your exact server is exploitable. Just update.
Attacks Started Within Hours
This vulnerability was exploited almost immediately:
- 22 September: The patch and advisory were published. The Hacker News reported the first exploitation attempt that same day at 11:49 UTC. Patchstack saw attackers start with harmless reconnaissance requests against core files.
- Next stage: Scanners probed for
pearcmd.phpat standard install paths. - By 24 September: Attackers were using
pearcmd.phpto write new PHP files to servers. Help Net Security reported that public scanning tools were circulating and that attack traffic had grown to more than ten times its initial level. - 25 September: The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-87902 to its Known Exploited Vulnerabilities (KEV) catalogue. US federal agencies were told to patch by 28 September.
How to Update to WordPress 7.1.2 (Step by Step)
Step 1: Check your current WordPress version
Go to Dashboard → Updates, or check the version shown at the bottom-right of any admin screen.
If your site has automatic background updates turned on, it may already have updated itself. The official announcement confirms that such sites “will start the update on their own.”
With WP-CLI:
bash
wp core version
Step 2: Take a full backup
Back up both files and the database before updating. Use your hosting panel’s backup tool or a backup plugin, and keep a copy off the server.
With WP-CLI you can export the database quickly:
bash
wp db export backup-before-7-1-2.sql
Step 3: Update WordPress core
Option A: From the dashboard Go to Dashboard → Updates → Update Now.
If WordPress asks for FTP details instead of updating, follow our guide on how to fix WordPress asking for FTP credentials. For more on update methods, see the official Updating WordPress documentation.
Option B: With WP-CLI (recommended for developers and agencies)
bash
# Update to the latest version
wp core update
# Update the database if WordPress asks for it
wp core update-db
# Confirm the new version
wp core version
If you need to stay on your current branch (for example 6.9.x), use the --minor flag to update to its latest security release instead:
bash
wp core update --minor
Option C: Manual update Download the latest release from WordPress.org and replace the core files. Don’t touch wp-content or wp-config.php.
Step 4: Verify core files
After updating, use wp core verify-checksums to confirm that no WordPress core file has been changed:
bash
wp core verify-checksums
If this reports modified or extra files in core folders, look into them before going further.
Step 5: Update themes and plugins, then clear caches
Update your theme and all plugins. Then purge your caching plugin, server cache and CDN (for example Cloudflare) so visitors get the patched site.
Extra Hardening Steps
Updating is the real fix. These extra steps reduce risk, especially if you manage your own VPS or can’t update right away.
1. Check whether your theme has a page- folder
bash
# Find the active theme
wp theme list --status=active --field=name
# Look for top-level folders starting with "page-" in that theme
ls -d wp-content/themes/YOUR-THEME/page-*/
If you use a child theme, check the parent theme as well.
2. Disable register_argc_argv for web requests
In your php.ini (or through your host’s PHP settings):
ini
register_argc_argv = Off
The command-line PHP configuration can differ from the one your website uses. Check the web setting through phpinfo() or your hosting control panel, not only with php -i.
3. Remove or restrict PEAR if you don’t need it
Check whether pearcmd.php exists on the server:
bash
find / -name "pearcmd.php" 2>/dev/null
If your sites don’t use PEAR, ask your host or server admin about removing it or blocking access to it.
4. Add a temporary WAF rule
As a stopgap until you patch, Patchstack suggests blocking traversal sequences such as %2e%2e in the pagename parameter. Use your firewall plugin, server WAF or Cloudflare rules for this. It doesn’t replace updating. For more on firewalls and other protections, read our best practices for improving web application security.
5. Turn on automatic security updates
Add this line to wp-config.php so future security releases install automatically. The official Upgrading WordPress handbook explains that the 'minor' value turns on minor (maintenance and security) updates and keeps major updates off:
php
define( 'WP_AUTO_UPDATE_CORE', 'minor' );
How to Check if Your Site Was Compromised
If your site was unpatched at any point on or after 22 September 2026, run these checks:
- Look for unexpected PHP files in temp folders. Patchstack recommends checking
/tmpand/var/tmp:
bash
find /tmp /var/tmp -name "*.php" 2>/dev/null
- Find recently changed PHP files in your site folder:
command bash
find /path/to/your/site -name "*.php" -mtime -10
- Search your access logs from 22 September onwards for requests containing
pearcmd,config-create, or traversal patterns such as%2e%2ein thepagenameparameter:
bash
grep -Ei "pearcmd|config-create|pagename=[^ ]*%2e%2e" /path/to/access.log
- Verify core file integrity with
wp core verify-checksums. - Review administrator accounts and remove any you don’t recognise:
bash
wp user list --role=administrator
- Run a full malware scan with a trusted security plugin or your host’s scanner.
If you find signs of compromise:
- Take the site offline or put it in maintenance mode.
- Restore from a clean backup taken before 22 September, then update to 7.1.2 straight away.
- Change all passwords: WordPress admin, hosting, FTP/SFTP and database.
- Regenerate the security keys and salts in
wp-config.phpusing the official WordPress secret-key generator.
If you’re not comfortable doing this yourself, bring in a professional. A half-cleaned site often gets reinfected.
Key Takeaways
- WordPress 7.1.2 fixes CVE-2026-87902, a critical (CVSS 9.2) unauthenticated path traversal bug in
get_page_template(). - Every version from 4.7.0 to 7.1.1 is affected, including 7.1.1.
- Fixes were backported to every branch down to 4.7.37. Update to the latest release in your branch at minimum.
- Attackers started probing the same day the patch came out, and CISA added the flaw to its KEV catalogue on 25 September.
- Full RCE needs specific conditions (a
page-theme folder,pearcmd.php,register_argc_argvon), but every affected site should update now. - If you patched late, check for unknown PHP files, strange log entries and new admin users.
FAQs
It’s a critical vulnerability in WordPress core that lets an attacker who isn’t logged in trick WordPress into loading a PHP file from outside the active theme’s folder. On servers with certain settings, this can lead to remote code execution.
WordPress 4.7.0 through 7.1.1. It’s fixed in WordPress 7.1.2, with backported fixes such as 7.0.6, 6.9.9 and 6.8.10, down to 4.7.37.
Yes. It’s an official security release, and the WordPress team recommends updating immediately. As with any update, take a backup first.
Yes. WooCommerce runs on WordPress core, so any store on WordPress 4.7.0–7.1.1 is affected until core is updated to a patched version. If you’re also updating WooCommerce this week, read WooCommerce 11.1: What Developers Need to Know.
Check that the version shows 7.1.2 (or the patched release for your branch). If the site was unpatched for any time after 22 September, run the compromise checks above.
Need help updating, securing or cleaning up your WordPress or WooCommerce website? We patch, harden and monitor WordPress sites for businesses across India. Get in touch for a quick security check.
Pradeep Maurya is the Professional Web Developer & Designer and the Founder of “Tutorials website”. He lives in Delhi and loves to be a self-dependent person. As an owner, he is trying his best to improve this platform day by day. His passion, dedication and quick decision making ability to stand apart from others. He’s an avid blogger and writes on the publications like Dzone, e27.co
