WordPress 7.1.2 Patch Stops Active Hacker Code Execution

Attackers are actively using a critical flaw to run commands on servers. Users must update to version 7.1.2 immediately to stop this.
Key points
- Hackers are actively exploiting CVE-2026-87902 to execute shell commands on WordPress sites.
- Malicious traffic increased tenfold after initial reconnaissance, moving to writing files to disk.
- Site administrators must update to WordPress 7.1.2 immediately and block identified attacker IPs.
Hackers are actively exploiting a critical security flaw in WordPress. This bug allows them to run malicious code on web servers. The vulnerability is known as CVE-2026-87902.
Malicious traffic began within five hours of the patch release. Attackers moved from simple scanning to writing harmful files to disk. This shift marks a significant escalation in risk for site owners.
Attackers escalate from scanning to execution
Security firm Patchstack reported the first malicious requests on September 22. These probes targeted sites to find those still vulnerable. The initial activity was limited to reconnaissance.
Traffic increased tenfold shortly after. Attackers began delivering payloads to write files to disk. These files can execute shell commands when accessed by users.
Understanding the path traversal risk
The flaw is an unauthenticated path traversal bug. It lets attackers include specific local PHP files outside theme directories. This leads to remote code execution under certain conditions.
The WordPress team rates this issue with a score of 9.2 out of 10. This indicates critical severity. The bug affects specific server configurations, including Docker images and older cPanel setups.
Required actions for site administrators
WordPress released version 7.1.2 to fix this flaw. The fix is also backported to versions down to 4.7. Releases before 4.6 will not receive this specific update.
BleepingComputer advises updating to 7.1.2 as soon as possible. Administrators should review server logs for signs of malicious activity. Specific IP addresses have been identified for blocking.






