Rewterz

IBM FTM Flaws Enable Code Execution

September 24, 2026
Rewterz

PHP Bug Could Leak Login Credentials

September 28, 2026

WordPress Flaw Enables Malicious Code Execution

Severity

High

Analysis Summary

WordPress has disclosed a critical unauthenticated local file inclusion vulnerability, CVE-2026-87902, affecting WordPress Core versions 4.7.0 through 7.1.1. The flaw exists in the page-template resolution process within the get_page_template() function, where the pagename parameter is insufficiently validated after URL decoding. By supplying path traversal sequences, unauthenticated attackers can escape the intended theme directory and force WordPress to include arbitrary local PHP files. The vulnerability has a CVSS score of high and requires neither authentication nor user interaction.

Active exploitation reportedly began on September 22, shortly after the security update was released, with attackers initially sending requests to benign WordPress core files to identify vulnerable installations. Within approximately a day, exploitation activity progressed toward PEAR's pearcmd.php utility, which can be abused to create attacker-controlled PHP files in temporary directories. Researchers observed attempts involving common pearcmd.php locations on Linux systems and container images, with files such as wp-pear-rce-flag.php, poc87902.php, and randomized luci_ and zeta_ filenames being written to /tmp and /var/tmp. Successful exploitation can potentially lead to remote code execution, particularly when PEAR is installed and PHP's register_argc_argv option is enabled.

The exploitation campaign has also become increasingly automated, with Researcher identifying user agents associated with public proof-of-concept exploits and Nuclei scanning activity. Attackers are varying traversal depth, encoding methods, HTTP request methods, and target URLs, making detection based on a single request pattern unreliable. Organizations should therefore treat unexpected PHP files in temporary directories and requests containing encoded traversal sequences or references to pearcmd.php as potential indicators of compromise. Even when created files are not directly accessible through the web, successful file creation demonstrates that the exploitation chain can execute on the affected server.

Organizations should immediately upgrade WordPress to version 7.1.2 or the appropriate patched release, including 7.0.6, 6.9.9, 6.8.10, or applicable backports down to 4.7.37. Until patching is completed, defenders should monitor and block suspicious traversal patterns in the pagename parameter, inspect web and application logs for encoded traversal attempts and pearcmd references, and examine /tmp and /var/tmp for unexpected PHP files. Disabling PHP's register_argc_argv option may disrupt the PEAR-based remote-code-execution chain, but it does not remediate the underlying local file inclusion vulnerability, making the WordPress security update the primary remediation.

Impact

  • Code Execution
  • Gain Access

Indicators of Compromise

CVE

  • CVE-2026-87902

Remediation

  • Immediately update WordPress Core to 7.1.2 or the appropriate patched release for the supported branch.
  • Upgrade older supported versions to 7.0.6, 6.9.9, 6.8.10, or the applicable backported release.
  • Monitor web server and WordPress logs for path traversal attempts in the pagename parameter.
  • Block suspicious or encoded traversal sequences such as ../ and related URL-encoded variants where appropriate.
  • Monitor for requests referencing pearcmd.php, particularly when combined with traversal patterns.
  • Inspect /tmp and /var/tmp for unexpected or recently created PHP files.
  • Investigate suspicious files such as wp-pear-rce-flag.php, poc87902.php, and other randomly named PHP files.
  • Check whether PEAR is installed and remove or restrict it if it is not required.
  • Disable PHP register_argc_argv where operationally possible to disrupt the PEAR-based exploitation chain.

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.