Stuart Neal
Director of Operations at Nextgen Marketing
We have worked with Vitalli and his team for well over a year now and will continue to do so in the future.
Having the confidence in an agency that allowed us to scale up and down development resources, as and when needed, has really made a positive difference to our agency.
Home / Blog / News / A WordPress core RCE is under active attack. Get every client site onto 7.1.2
This one is core, not a plugin. CVE-2026-87902 is an unauthenticated path traversal in WordPress’s page-template resolution, rated CVSS 9.2, fixed in WordPress 7.1.2 on September 22 — and according to Patchstack’s own attack telemetry, the first exploit attempts arrived at 11:49 UTC the same day, built from the patch diff rather than from independent discovery. This is the scenario that patching a whole client portfolio the day a fix lands exists for.
Exploitation is conditional, which is why “critical” doesn’t mean “every site”:
Stage three of what Patchstack observed is attackers using config-create to write a file of their choosing, with content they control, to disk. That is a shell, not a proof of concept.
Six days between the patch and today is a long window when exploitation started on day zero. If a site was vulnerable and internet-facing, updating closes the hole but does not undo anything that already happened — that part needs a look at the logs.
If you’re on one of our maintenance plans, 7.1.2 is already applied across your sites and it will appear as its own line in your next monthly maintenance report, along with the theme check and the log review for this specific CVE. There is nothing for you to action. If you’re not on a plan, this is a fair illustration of the gap one closes: the patch shipped on a Tuesday, attackers were probing for it by lunchtime, and the difference between a patched site and a compromised one came down to who was watching that week.
Source: Patchstack