WordPress Patches CVE-2026-87902 Unauthenticated Code Execution Flaw

Élevé · Help Net Security ·

WordPress

Vérification: The article is future-dated at 2026-09-23, ahead of the current date, and describes an unverifiable future WordPress release and CVE.

En bref

  • CVE-2026-87902 affects WordPress 4.7.0 through 7.1.1.
  • An unauthenticated attacker can exploit path traversal to load a PHP file.
  • Successful exploitation can lead to code execution and full server compromise.
  • WordPress 7.1.2 resolves the issue; update immediately.
  • Disclosure date: 23 September 2026.

WordPress maintainers published version 7.1.2 on 23 September 2026 to resolve a high-severity security defect tracked as CVE-2026-87902. The issue affects every release from 4.7.0 up to and including 7.1.1. According to the advisory, an attacker who has not authenticated can abuse a directory traversal weakness to cause the platform to load a PHP file of their choosing, which then executes on the underlying server.

The flaw matters because it requires no credentials and can be triggered remotely. If exploited, it could allow an intruder to run arbitrary code, potentially leading to full server compromise. That risk is especially acute for K-12 districts and government agencies that host public-facing WordPress sites, where a single vulnerable installation could expose student data, internal services, or other connected systems.

The vendor has already shipped a patched release, 7.1.2. Administrators should treat this as an urgent update. Because the vulnerable range spans many years of WordPress versions, older, unmaintained sites are likely to be at greatest risk. Sites that cannot be updated immediately should be isolated or taken offline until remediation is possible.

Context: This is not the first time path traversal has appeared in WordPress core or plugins, but an unauthenticated code execution bug in core is rare and serious. The broad version range means many organizations may have forgotten installations still running legacy code. The disclosure date gives defenders a clear timeline for checking logs and patch status.

What to watch: Monitor for unexpected PHP file writes, unusual outbound connections, or new administrative accounts. Also watch for public proof-of-concept exploits, which often appear within days of a high-profile WordPress disclosure. Verify that all WordPress instances, including staging and forgotten subdomains, are running 7.1.2 or a later fixed version.

À faire maintenant

  1. Update every WordPress installation to version 7.1.2 or later as the top priority.
  2. Identify all sites still running versions 4.7.0 through 7.1.1, including staging and forgotten instances.
  3. If immediate patching is not possible, take vulnerable sites offline or restrict access with a WAF or authentication layer.
  4. Review web server and application logs for directory traversal attempts and unexpected PHP file creation.
  5. Check for signs of compromise such as new admin accounts, modified core files, or suspicious outbound traffic.
  6. Apply virtual patching rules if your WAF supports them, and rotate credentials if you suspect exploitation.
  7. After patching, verify that no backdoors or unauthorized scheduled tasks remain on affected servers.

Références CVE

  • CVE-2026-87902

Source originale

Help Net Security

Analyse originale assistée par IA, sources citées. Vérifiez auprès de l'avis du fournisseur avant d'agir.

← Toute la veille cyber