← All articles
BREAKING

WordPress flaw exploited within hours

A critical WordPress bug was under attack within hours of its fix. If your business website runs on WordPress, check it's on 7.1.2 today.

Sophia, HackRisk's AI security analyst, in a small web design studio pointing at a WordPress 7.1.2 update completing on a freelancer's monitor, with the headline 'WordPress flaw exploited within hours'

If your business website runs on WordPress, there's one job for today: check it's on version 7.1.2 (or the matching security release for your branch). A critical flaw fixed on 22 September was being attacked within hours of the fix going out, and the attacks have been growing since.

What happened

WordPress has released version 7.1.2 to fix CVE-2026-87902, a flaw in the way WordPress picks which page template to load. It was responsibly disclosed by security researcher Robert Ressl, and it carries a severity score of 9.2 out of 10 (CVSS v4), which puts it in the critical band. Help Net Security reports that every version from 4.7.0 through 7.1.1 is affected, and the fix has been backported to 24 older branches, from 7.0.6 all the way down to 4.7.37.

Attackers moved fast. According to Field Effect, exploitation attempts began within hours of the release. The Hacker News puts the first attempt at 11:49 UTC on 22 September, with 68 attempts recorded in its telemetry by the next day. By 24 September, Help Net Security reported that attack traffic had grown to more than ten times its initial level. In the US, CISA added the flaw to its Known Exploited Vulnerabilities catalogue on 25 September.

It also comes hot on the heels of WordPress 7.1.1, released on 17 September to fix two other security flaws. That's two security releases in under a week, so if your site was last updated at the start of the month, it's behind on both.

How the attack works

When someone visits a page, WordPress looks inside your theme for the right template file. This bug lets a specially crafted web request trick that lookup into walking out of the theme folder and loading a different PHP file elsewhere on the server. That's what security people call path traversal.

On its own, loading a file sounds harmless. The problem is which file. Attackers are pointing WordPress at a standard server tool called pearcmd.php, which comes with many PHP installations, and using it to write new PHP files to disk. Those files are web shells: small back doors that let the attacker run commands on your server whenever they like.

Who is actually at risk?

Not every WordPress site can be fully taken over. The sources agree two conditions must be met: the active theme has a top-level folder whose name starts with “page-”, and a readable PHP file like pearcmd.php exists on the server. Field Effect and BetaNews name Twenty Twelve, Twenty Fourteen, Neve, Hestia and Sydney as themes with that folder structure. But no login, password or click is needed, and attackers are scanning widely, so the safe assumption is: if you're not updated, you're a candidate.

What this means for UK small businesses

WordPress runs a huge number of UK small-business websites, and many of them were built by a freelancer or agency years ago and haven't had much love since. Nobody is quite sure who's responsible for updates, whether automatic updates are switched on, or which theme is in use.

That's exactly the gap this kind of attack exploits. The time between a fix being published and criminals using it is now measured in hours, not weeks. A web shell on your site can be used to steal customer data from contact forms, inject malicious code into pages your customers visit, or quietly use your server to attack others, all while your site looks perfectly normal.

What to do this week

Check your version today. Log in to your WordPress dashboard and go to Dashboard → Updates. You want 7.1.2, or 7.0.6, 6.9.9, 6.8.10 or the matching security release for an older branch. If you don't have access, ask whoever looks after your site to confirm in writing.

Switch on automatic background updates. Sites with automatic security updates enabled should have received the fix on their own. Make sure yours is one of them, and that your hosting hasn't disabled it.

Look for anything that's been planted. Ask your developer or host to check for newly created PHP files in writable folders (such as upload and temp directories) since 22 September, and to review web logs for odd requests. Field Effect suggests looking for requests combining page_id and pagename with double-encoded traversal strings.

Find the sites you've forgotten about. Old campaign microsites, staging copies and “test” installs on subdomains are rarely updated. Either update them or take them down.

Agree who owns updates. Put it in writing: who patches the site, how quickly after a critical release, and who you'll hear from when it's done.

Sophia Says

“What worries me about this one isn't the bug itself. Bugs happen, and the WordPress team patched it properly, all the way back to version 4.7. It's the speed. Attackers were trying it within hours. Most small businesses I talk to check their website once in a blue moon, and they're assuming someone else has it covered. That assumption is now the weakest part of the site.”
“That's what HackRisk is there for. Our Vulnerability Scan spots outdated WordPress versions from the outside, with nothing to install, and tells you in plain English what to fix first. Recon Scan finds the forgotten installs on subdomains that nobody remembers owning. And because we keep watching, you hear about the next critical release while it still matters, not weeks later.”
— Sophia, HackRisk AI Security Analyst

Where HackRisk fits

Vulnerability Scan checks your internet-facing websites for outdated software like vulnerable WordPress versions and tells you what to fix first.

Recon Scan maps everything you expose to the internet, including old WordPress installs, staging sites and subdomains that slipped off the list.

Dark Web Scan watches for your business's credentials and customer data turning up where they shouldn't, so you know fast if a compromised site has leaked anything.

Supply Chain Risk keeps an eye on the agencies, hosts and platforms your website depends on, so their gaps don't become yours.

Is your website up to date?

Find out what attackers can see when they look at your business online. Get your free HackRisk report and see which of your sites need attention, with no credit card needed.

Sources