Back to the desk

Advisory summary

Critical WordPress flaw exploited within hours of its patch; update to 7.1.2 now

Severity: CriticalPublished Latest development GlobalAdvisory2026-0925-WP02 min readBy Vivek Kumar
Conceptual illustration: Glass website pages and plug-in blocks with one fractured connector receiving a patch. Headline: WEB APP SECURITY.

AI-generated editorial illustration by CyberShitty. Not a photograph or a document from the organisations named.

An unauthenticated WordPress core bug (CVE-2026-87902) can lead to code execution on some sites. Attack traffic began less than five hours after the fix; CERT-In rates it critical and CISA lists it as exploited.

01 / What happened

WordPress released version 7.1.2 on 22 September 2026 as a security release fixing a critical vulnerability, now tracked as CVE-2026-87902. According to the WordPress security team, an unauthenticated attacker can, under certain conditions, make page template resolution include a chosen readable local PHP file outside the active theme's directories. If the server environment and the active theme meet the right preconditions, that can lead to remote code execution. WordPress backported the fix to older branches that still receive security updates.

The WordPress team rates the flaw 9.2 out of 10. CERT-In issued vulnerability note CIVN-2026-0472 on 23 September, rating it critical. On 25 September the US Cybersecurity and Infrastructure Security Agency added it to its Known Exploited Vulnerabilities catalogue, with a 28 September deadline for federal agencies.

02 / How fast attacks started

WordPress security firm Patchstack told BleepingComputer it saw the first malicious requests at 17:44 UTC on 22 September, less than five hours after the patch came out. The early traffic tried to include ordinary WordPress core files, apparently to find vulnerable sites. Later attempts wrote files to /tmp and /var/tmp.

Five hours from patch to probing: for an internet-facing CMS, 'we'll update this weekend' is already too late.

03 / Who is exposed

Any self-hosted WordPress site that has not applied 7.1.2 or the patched release for its branch, where the server and theme meet the conditions for exploitation. That includes a large share of Indian small business, school, clinic, NGO and news sites, many of them run by agencies or freelancers and updated irregularly. Sites on managed hosts that apply core updates automatically are likely to be patched already, but you should confirm rather than assume. Our KEV digest for 25 September lists the CISA entry.

04 / Confirmed vs. claimed

Confirmed: the vulnerability and fix (WordPress), critical severity (WordPress and CERT-In) and exploitation in the wild (CISA's KEV listing). Reported by a security firm: the timing and pattern of attack traffic (Patchstack via BleepingComputer). No attacker has been named, and we have not seen a count of compromised sites.

05 / What to do now

  • Update to WordPress 7.1.2, or the latest security release of your branch, today. Check the version in Dashboard, Updates rather than trusting auto-update settings.
  • Look for unexpected .php files in /tmp, /var/tmp and wp-content/uploads, and for recently changed files in your themes.
  • Review web server logs from 22 September onwards for unusual page-template or path traversal requests.
  • Delete themes you do not use, and keep plugins and PHP up to date.
  • If you find signs of compromise, restore from a clean backup, rotate all admin, database and hosting passwords, and report the incident. Organisations covered by CERT-In's directions must report within six hours: how to report to CERT-In.

Source log / 2026-0925-WP

More from the archive