Severity
High
Analysis Summary
WordPress has disclosed a critical unauthenticated local file inclusion vulnerability, CVE-2026-87902, affecting WordPress Core versions 4.7.0 through 7.1.1. The flaw exists in the page-template resolution process within the get_page_template() function, where the pagename parameter is insufficiently validated after URL decoding. By supplying path traversal sequences, unauthenticated attackers can escape the intended theme directory and force WordPress to include arbitrary local PHP files. The vulnerability has a CVSS score of high and requires neither authentication nor user interaction.
Active exploitation reportedly began on September 22, shortly after the security update was released, with attackers initially sending requests to benign WordPress core files to identify vulnerable installations. Within approximately a day, exploitation activity progressed toward PEAR's pearcmd.php utility, which can be abused to create attacker-controlled PHP files in temporary directories. Researchers observed attempts involving common pearcmd.php locations on Linux systems and container images, with files such as wp-pear-rce-flag.php, poc87902.php, and randomized luci_ and zeta_ filenames being written to /tmp and /var/tmp. Successful exploitation can potentially lead to remote code execution, particularly when PEAR is installed and PHP's register_argc_argv option is enabled.
The exploitation campaign has also become increasingly automated, with Researcher identifying user agents associated with public proof-of-concept exploits and Nuclei scanning activity. Attackers are varying traversal depth, encoding methods, HTTP request methods, and target URLs, making detection based on a single request pattern unreliable. Organizations should therefore treat unexpected PHP files in temporary directories and requests containing encoded traversal sequences or references to pearcmd.php as potential indicators of compromise. Even when created files are not directly accessible through the web, successful file creation demonstrates that the exploitation chain can execute on the affected server.
Organizations should immediately upgrade WordPress to version 7.1.2 or the appropriate patched release, including 7.0.6, 6.9.9, 6.8.10, or applicable backports down to 4.7.37. Until patching is completed, defenders should monitor and block suspicious traversal patterns in the pagename parameter, inspect web and application logs for encoded traversal attempts and pearcmd references, and examine /tmp and /var/tmp for unexpected PHP files. Disabling PHP's register_argc_argv option may disrupt the PEAR-based remote-code-execution chain, but it does not remediate the underlying local file inclusion vulnerability, making the WordPress security update the primary remediation.
Impact
- Code Execution
- Gain Access
Indicators of Compromise
CVE
CVE-2026-87902
Remediation
- Immediately update WordPress Core to 7.1.2 or the appropriate patched release for the supported branch.
- Upgrade older supported versions to 7.0.6, 6.9.9, 6.8.10, or the applicable backported release.
- Monitor web server and WordPress logs for path traversal attempts in the pagename parameter.
- Block suspicious or encoded traversal sequences such as ../ and related URL-encoded variants where appropriate.
- Monitor for requests referencing pearcmd.php, particularly when combined with traversal patterns.
- Inspect /tmp and /var/tmp for unexpected or recently created PHP files.
- Investigate suspicious files such as wp-pear-rce-flag.php, poc87902.php, and other randomly named PHP files.
- Check whether PEAR is installed and remove or restrict it if it is not required.
- Disable PHP register_argc_argv where operationally possible to disrupt the PEAR-based exploitation chain.

