Threat actors are actively exploiting WordPress CVE-2026-87902, a critical remote code execution vulnerability, within hours of its public disclosure. The attacks target servers meeting specific preconditions and use local PHP files like pearcmd.php to execute malicious code, with over 68 exploitation attempts recorded from multiple countries since September 22, 2026.
WordPress patched a critical vulnerability (CVE-2026-87902, CVSS 9.2) affecting versions 4.7.0 through 7.1.1 that allows unauthenticated attackers to load external PHP files, potentially enabling code execution on some servers. The fix shipped September 22 across all supported branches, and site owners are urged to update immediately as no workaround exists.