wordpress-core-rce

A WordPress site can be taken over by an attacker without a password: a critical vulnerability in the WordPress core is already being exploited in real-world attacks, and a fix is available in version 7.1.2.

This is CVE-2026-87902, a “path traversal” vulnerability in the WordPress core. Under certain conditions, an unauthenticated attacker can cause the server to include and execute a file of their choice, which leads to the execution of commands on the server—that is, to the takeover of the site. The vulnerability has been assigned a critical severity rating.

These attacks are real and on the rise. Security researchers first observed a reconnaissance phase, during which attackers searched for vulnerable sites, followed by a shift toward writing files that execute commands when accessed. Malicious traffic has increased tenfold, and some payloads leave trap files in the server’s temporary folders.

WordPress released the fix in version 7.1.2 and also applied the correction to older versions, back to 4.7, precisely because of the severity of the issue. An important note for companies hosted on standard servers: the default cPanel configuration is affected when using a version of PHP older than 8.5.

WordPress powers most business websites, from simple homepages to online stores. A compromised website can be used to steal customer data, redirect visitors to fake pages, or spread malicious code—all in your company’s name.

What you need to do:

  • Update every WordPress site to version 7.1.2.
  • If you use automatic updates, make sure to actually check that they have been applied—don’t just assume they have.
  • Ask the company or person who maintains your site to confirm the fix and check the server for suspicious files.
  • If possible, upgrade PHP to version 8.5.

A website that “works” can go for months without being touched, which is exactly why an unpatched vulnerability becomes an open door. A quick check will tell you if you’re at risk.

This article was generated with AI assistance.

Request a quote

← All news