Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
WordPress Vulnerability Exploited Rapidly After Reveal

WordPress Vulnerability Exploited Rapidly After Reveal

Posted on September 24, 2026 By CWS

A newly disclosed vulnerability in WordPress has seen swift exploitation, with active compromises occurring shortly after its public announcement, according to cybersecurity firm Patchstack.

Details of the Vulnerability

The vulnerability, identified as CVE-2026-87902 with a CVSS score of 9.2, is a path traversal flaw within WordPress’ page-template resolution system. This flaw potentially allows unauthenticated attackers to execute remote code under specific conditions.

According to WordPress, the security issue can be exploited when an attacker makes the get_page_template() function include a predefined, readable local .php file from outside the active theme directories. This can lead to remote code execution if certain server and theme conditions are satisfied.

Conditions for Exploitation

The security risk arises when the top-level directory name of the active child or parent theme begins with ‘page-‘. Additionally, if the server account can read a specific local .php target file, the vulnerability can be triggered.

Particularly, the well-known pearcmd.php in PEAR can be leveraged for remote code execution when the register_argc_argv setting is enabled. This affects the official PHP Docker image and the default cPanel setup when using PHP versions prior to 8.5.

Impact and Response

The flaw impacts themes with certain directory layouts, including WordPress’ older themes like Twenty Twelve and Twenty Fourteen, as well as third-party themes such as Neve, Hestia, and Sydney. WordPress addressed this security issue in version 7.1.2 on September 22, with patches backported to earlier versions down to 4.7.x.

Patchstack reports that exploitation attempts began mere hours after the vulnerability was disclosed, initially for reconnaissance. By September 23, these attempts had escalated to actual compromises, originating from a small group of IP addresses.

The volume of malicious traffic targeting this vulnerability has significantly increased, spreading across a wider range of websites. The attack process involves initial vulnerability verification, followed by PEAR inclusion checks, and ends with abusing pearcmd.php to execute remote code.

Considering the availability of public scanning tools, Patchstack anticipates a rise in activities surrounding CVE-2026-87902. Website administrators are urged to update their WordPress installations and apply necessary security measures to safeguard against potential attacks.

For further information on recent security updates, see related articles on WordPress’ Click2Shell patch, Adobe’s critical flaw fixes, and the urgent patching of Arista’s VCO zero-day.

Security Week News Tags:cPanel, CVE-2026-87902, Cybersecurity, Docker, Patchstack, path traversal, PEAR, PHP, remote code execution, Security, theme security, Vulnerability, web security, website protection, WordPress

Post navigation

Previous Post: Apache Tomcat 11.0.26 Enhances Security with Critical Fixes
Next Post: AI Agent Breaches Australian Medicare Portal Controls

Related Posts

574 Arrested,  Million Seized in Crackdown on African Cybercrime Rings 574 Arrested, $3 Million Seized in Crackdown on African Cybercrime Rings Security Week News
Over 30 Vulnerabilities Patched in Android Over 30 Vulnerabilities Patched in Android Security Week News
AirMDR Raises .5 Million for MDR Solution AirMDR Raises $15.5 Million for MDR Solution Security Week News
North Korean Hackers Take Over Victims’ Systems Using Zoom Meeting North Korean Hackers Take Over Victims’ Systems Using Zoom Meeting Security Week News
Recent Langflow Vulnerability Exploited by Flodrix Botnet Recent Langflow Vulnerability Exploited by Flodrix Botnet Security Week News
Vulnerabilities Expose Helmholz Industrial Routers to Hacking Vulnerabilities Expose Helmholz Industrial Routers to Hacking Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Konni Malware Campaign Targets Ukrainian Entities with Fake PDFs
  • Agentic Remediation: Closing the Loop in Cybersecurity
  • WordPress Security Flaw CVE-2026-87902 Under Attack
  • AI-Powered Android Trojan Targets Banking Apps
  • AI-Driven Attacks Threaten Online Retail Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Konni Malware Campaign Targets Ukrainian Entities with Fake PDFs
  • Agentic Remediation: Closing the Loop in Cybersecurity
  • WordPress Security Flaw CVE-2026-87902 Under Attack
  • AI-Powered Android Trojan Targets Banking Apps
  • AI-Driven Attacks Threaten Online Retail Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark