The WordPress core file-inclusion flaw patched on 22 September is now being exploited
EditorialBy TrustList Editorial
CISA added CVE-2026-87902 to its exploited list on 25 September with a 28 September deadline. Every WordPress release from 4.7.0 to 7.1.1 is affected; 7.1.2 and matching branch releases fix it. Confirm each site actually updated.
About The WordPress core file-inclusion flaw patched on 22 September is now being exploited
The WordPress core file-inclusion flaw patched on 22 September is now being exploited
25 September 2026 — CISA added CVE-2026-87902, a flaw in WordPress core, to its Known Exploited Vulnerabilities catalogue on 25 September 2026, in a separate alert from the SharePoint and MikroTik additions of the same day. US federal agencies must fix it by 28 September. WordPress released the fix on 22 September; attacks followed within days, and the question for most businesses is no longer whether to update but whether every site actually did.
Not yet independently verified. The time of the first exploitation attempt (11:49 UTC on 22 September, the day of the fix) is attributed to the security firm Patchstack by one outlet only; we have not read Patchstack’s own report. That exploitation is happening rests on CISA’s catalogue. We will update this when it can be confirmed, and remove this note.
What the flaw does
WordPress's advisory rates the flaw critical, 9.2 out of 10. An attacker who is not logged in can make WordPress's page-template lookup include a PHP file of their choosing from elsewhere on the server. On its own that runs whatever the chosen file does; with the right server set-up it becomes code execution. The advisory names the conditions:
- the active theme or its parent contains a top-level folder whose name starts with
page-, as Twenty Twelve, Twenty Fourteen, Neve, Hestia and Sydney do; - a usable PHP file is present, the known route being PEAR's
pearcmd.phpwith PHP'sregister_argc_argvsetting switched on; - Security Affairs reports that those server conditions are met by default in the official PHP Docker images and in cPanel set-ups running PHP older than 8.5.
Every WordPress release from 4.7.0 to 7.1.1 is affected, nearly ten years of versions. Fixed releases exist for every affected branch, from 4.7.37 up to 7.1.2.
Who is affected
Any business with a WordPress website, which includes many that do not think of themselves as running software: marketing sites built by an agency, landing pages on shared hosting, and old microsites nobody has touched in years. WordPress installs security releases automatically unless that has been turned off, so most maintained sites will already be fixed; the risk sits with sites where automatic updates were disabled, hosts that pin versions, and forgotten installs.
What to do
- List every WordPress site you own or pay for, including old campaign sites, and check that each is on 7.1.2 or the fixed release for its branch.
- Where automatic updates are off, update by hand now, and ask why they were turned off.
- If you use one of the named themes, or a theme with a
page-folder, treat an unpatched site as possibly compromised and look for unfamiliar PHP files and administrator accounts. - Ask your hosting provider whether
register_argc_argvis on and whether PEAR is installed, and to disable them if they are not needed. - If an agency maintains your sites, ask it in writing for the version of each site and the date it was updated.
Sources
- CISA: CISA Adds One Known Exploited Vulnerability to Catalog — 25 September 2026
- WordPress security advisory GHSA-7hp8-65ch-5whp / CVE-2026-87902 — 22 September 2026
- Security Affairs: CVE-2026-87902, how close is your WordPress to remote code execution? — 23 September 2026
- Tech Insider: WordPress CVE-2026-87902 exploited within hours — 24 September 2026
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.