# WordPress RCE flaw exploited in the wild

Published: 2026-10-01 · Severity: high · Sectors: technology, government-national
Canonical: https://vorant.io/reports/6866a070-fc24-5b0d-89bb-f4b7ed9719d3/wordpress-rce-flaw-exploited-in-the-wild

> An unauthenticated local file inclusion flaw in WordPress's page-template resolution, CVE-2026-87902, is actively exploited and listed in CISA's KEV catalog.

CIS/MS-ISAC issued an advisory on CVE-2026-87902, a vulnerability in WordPress core affecting versions prior to 7.1.2. The flaw resides in the get_page_template() page-template resolution logic, which an unauthenticated attacker can manipulate to include an arbitrary, readable local .php file located outside the active theme directory. Under specific server and theme preconditions, this local file inclusion can escalate to full remote code execution on the web server.

Public exploit code is available and CISA has added this CVE to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild. Given WordPress's massive install base across government, business, and personal websites, this represents a broad attack surface for opportunistic scanning and exploitation. The attack requires no authentication, lowering the barrier for exploitation significantly.

Defenders running WordPress should prioritize patching to version 7.1.2 or later immediately. Standard hardening measures apply: least-privilege execution for web server processes, network segmentation isolating web-facing assets, vulnerability scanning, and anti-exploitation controls. Organizations should treat this as a high-priority patching action given confirmed in-the-wild exploitation and public exploit availability.

## Mentioned in this report

- Vulnerabilities: CVE-2026-87902 (KEV)

## Detection guidance (public sample)

### Linux Web Server or PHP Process Spawning Shell With Recon or Download Commands

ATT&CK: T1190

PHP or web server worker processes spawning a shell that runs recon or payload-download commands, typical post-exploitation of a WordPress RCE such as CVE-2026-87902. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: Linux Web Server or PHP Process Spawning Shell With Recon or Download Commands
id: 8d48e702-a285-53c2-b1fa-c8a1be63cfc5
status: experimental
description: Detects a PHP or web server worker (php-fpm, php-cgi, apache, nginx)
  spawning a shell that runs reconnaissance or download-and-execute commands. This
  is the typical follow-on to successful RCE in a public-facing WordPress site (CVE-2026-87902
  local file inclusion escalating to code execution). Generalises on the parent/child
  relation and command content, not on any exploit-specific path.
references:
- https://www.cisecurity.org/advisory/a-vulnerability-in-wordpress-could-allow-for-remote-code-execution_2026-106
tags:
- attack.initial-access
- attack.t1190
logsource:
  category: process_creation
  product: linux
detection:
  selection_parent:
    ParentImage|endswith:
    - /php-fpm
    - /php-fpm7
    - /php-fpm8
    - /php-cgi
    - /php
    - /apache2
    - /httpd
    - /nginx
    - /lsphp
  selection_child:
    Image|endswith:
    - /sh
    - /bash
    - /dash
    - /busybox
  selection_cmd:
    CommandLine|contains:
    - whoami
    - uname -a
    - id;
    - /etc/passwd
    - curl
    - wget
    - nc -e
    - /dev/tcp/
    - base64 -d
    - chmod +x
    - python -c
    - perl -e
  filter_mail:
    CommandLine|contains:
    - sendmail
    - /usr/sbin/exim
  condition: selection_parent and selection_child and selection_cmd and not filter_mail
falsepositives:
- Plugins that shell out to curl or wget for update checks or backups from PHP
- Admin-installed WordPress management tooling that invokes shell commands through
  PHP
level: high
author: Vorant
```

### Windows PHP or Web Server Worker Spawning Command Interpreter

ATT&CK: T1190

php-cgi, php, httpd or w3wp spawning cmd or PowerShell with recon or download commands, indicating code execution through a vulnerable WordPress site. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: Windows PHP or Web Server Worker Spawning Command Interpreter
id: f056fce3-e9bd-5bf9-959d-7a86447725c4
status: experimental
description: Detects PHP handlers or web server workers (php-cgi, php, httpd, w3wp,
  nginx) spawning cmd.exe or PowerShell with discovery or download-cradle arguments.
  Indicates post-exploitation after RCE against a WordPress host such as CVE-2026-87902.
  Generalises on the parent/child relation and command content, not on specific payloads.
references:
- https://www.cisecurity.org/advisory/a-vulnerability-in-wordpress-could-allow-for-remote-code-execution_2026-106
tags:
- attack.initial-access
- attack.t1190
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|endswith:
    - \php-cgi.exe
    - \php.exe
    - \httpd.exe
    - \w3wp.exe
    - \nginx.exe
  selection_child:
    Image|endswith:
    - \cmd.exe
    - \powershell.exe
    - \pwsh.exe
  selection_cmd:
    CommandLine|contains:
    - whoami
    - net user
    - net localgroup
    - systeminfo
    - ipconfig
    - certutil
    - bitsadmin
    - Invoke-WebRequest
    - DownloadString
    - IEX
    - -enc
    - curl
  condition: all of selection_*
falsepositives:
- Administrators running diagnostic commands through a PHP-based admin panel
- Backup or deployment scripts invoked by PHP on Windows-hosted WordPress
level: high
author: Vorant
```

Behavioural rules are generated from public reporting — validate in your environment before deploying.

Source reporting: https://www.cisecurity.org/advisory/a-vulnerability-in-wordpress-could-allow-for-remote-code-execution_2026-106

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/6866a070-fc24-5b0d-89bb-f4b7ed9719d3/wordpress-rce-flaw-exploited-in-the-wild.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
