VORANT. Threat Intelligence Research Sign in Create a free account

WordPress RCE flaw exploited in the wild

high vulnerability technologygovernment-national

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

An unauthenticated local file inclusion flaw in WordPress's page-template resolution, CVE-2026-87902, is actively exploited and listed in CISA's KEV catalog.

CIS/MS-ISAC issued an advisory on CVE-2026-87902, a vulnerability in WordPress core affecting versions prior to 7.1.2. The flaw resides in the get_page_template() page-template resolution logic, which an unauthenticated attacker can manipulate to include an arbitrary, readable local .php file located outside the active theme directory. Under specific server and theme preconditions, this local file inclusion can escalate to full remote code execution on the web server.

Public exploit code is available and CISA has added this CVE to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild. Given WordPress's massive install base across government, business, and personal websites, this represents a broad attack surface for opportunistic scanning and exploitation. The attack requires no authentication, lowering the barrier for exploitation significantly.

Defenders running WordPress should prioritize patching to version 7.1.2 or later immediately. Standard hardening measures apply: least-privilege execution for web server processes, network segmentation isolating web-facing assets, vulnerability scanning, and anti-exploitation controls. Organizations should treat this as a high-priority patching action given confirmed in-the-wild exploitation and public exploit availability.

Mentioned in this report

Vulnerabilities CVE-2026-87902KEV

Detection guidance

Linux Web Server or PHP Process Spawning Shell With Recon or Download Commands

ATT&CK T1190

PHP or web server worker processes spawning a shell that runs recon or payload-download commands, typical post-exploitation of a WordPress RCE such as CVE-2026-87902. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

title: Linux Web Server or PHP Process Spawning Shell With Recon or Download Commands
id: 8d48e702-a285-53c2-b1fa-c8a1be63cfc5
status: experimental
description: Detects a PHP or web server worker (php-fpm, php-cgi, apache, nginx)
  spawning a shell that runs reconnaissance or download-and-execute commands. This
  is the typical follow-on to successful RCE in a public-facing WordPress site (CVE-2026-87902
  local file inclusion escalating to code execution). Generalises on the parent/child
  relation and command content, not on any exploit-specific path.
references:
- https://www.cisecurity.org/advisory/a-vulnerability-in-wordpress-could-allow-for-remote-code-execution_2026-106
tags:
- attack.initial-access
- attack.t1190
logsource:
  category: process_creation
  product: linux
detection:
  selection_parent:
    ParentImage|endswith:
    - /php-fpm
    - /php-fpm7
    - /php-fpm8
    - /php-cgi
    - /php
    - /apache2
    - /httpd
    - /nginx
    - /lsphp
  selection_child:
    Image|endswith:
    - /sh
    - /bash
    - /dash
    - /busybox
  selection_cmd:
    CommandLine|contains:
    - whoami
    - uname -a
    - id;
    - /etc/passwd
    - curl
    - wget
    - nc -e
    - /dev/tcp/
    - base64 -d
    - chmod +x
    - python -c
    - perl -e
  filter_mail:
    CommandLine|contains:
    - sendmail
    - /usr/sbin/exim
  condition: selection_parent and selection_child and selection_cmd and not filter_mail
falsepositives:
- Plugins that shell out to curl or wget for update checks or backups from PHP
- Admin-installed WordPress management tooling that invokes shell commands through
  PHP
level: high
author: Vorant

Windows PHP or Web Server Worker Spawning Command Interpreter

ATT&CK T1190

php-cgi, php, httpd or w3wp spawning cmd or PowerShell with recon or download commands, indicating code execution through a vulnerable WordPress site. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

title: Windows PHP or Web Server Worker Spawning Command Interpreter
id: f056fce3-e9bd-5bf9-959d-7a86447725c4
status: experimental
description: Detects PHP handlers or web server workers (php-cgi, php, httpd, w3wp,
  nginx) spawning cmd.exe or PowerShell with discovery or download-cradle arguments.
  Indicates post-exploitation after RCE against a WordPress host such as CVE-2026-87902.
  Generalises on the parent/child relation and command content, not on specific payloads.
references:
- https://www.cisecurity.org/advisory/a-vulnerability-in-wordpress-could-allow-for-remote-code-execution_2026-106
tags:
- attack.initial-access
- attack.t1190
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|endswith:
    - \php-cgi.exe
    - \php.exe
    - \httpd.exe
    - \w3wp.exe
    - \nginx.exe
  selection_child:
    Image|endswith:
    - \cmd.exe
    - \powershell.exe
    - \pwsh.exe
  selection_cmd:
    CommandLine|contains:
    - whoami
    - net user
    - net localgroup
    - systeminfo
    - ipconfig
    - certutil
    - bitsadmin
    - Invoke-WebRequest
    - DownloadString
    - IEX
    - -enc
    - curl
  condition: all of selection_*
falsepositives:
- Administrators running diagnostic commands through a PHP-based admin panel
- Backup or deployment scripts invoked by PHP on Windows-hosted WordPress
level: high
author: Vorant

Behavioural rules are generated from public reporting — validate in your environment before deploying.

Source reporting: https://www.cisecurity.org/advisory/a-vulnerability-in-wordpress-could-allow-for-remote-code-execution_2026-106

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 10,582 reports from 152 sources, 502 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs