CVE-2026-87902: Attackers Started Probing WordPress Sites Hours After the Patch
Reported exploitedWordPress CoreOur summary
Patchstack observed active probing for CVE-2026-87902 less than five hours after WordPress 7.1.2 was released. The unauthenticated path traversal flaw affects WordPress Core 4.7.0 to 7.1.1 and can lead to local file inclusion and, under certain server conditions, RCE; administrators should update to 7.1.2, 7.0.6, 6.9.9, 6.8.10, or the applicable backport through 4.7.37.
Below is the opening; the full story is at Patchstack.
From Patchstack
Earlier today we wrote up CVE-2026-87902, the unauthenticated local file inclusion in WordPress page template resolution fixed in 7.1.2. That post covered the sink, the preconditions and the fix. This is the follow-up, because the issue was already being probed in the wild before the day was over.
Patchstack customers are protected by a RapidMitigate rule. If you have not updated yet, WordPress 7.1.2 or the patched release on your branch remains the fix.…
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.