Day-one probes. Day-two pearcmd writes. That is the board brief.
On September 22 WordPress shipped 7.1.2 for CVE-2026-87902 / GHSA-7hp8-65ch-5whp: unauthenticated page-template path traversal / LFI that can reach RCE when theme and PHP preconditions are met (CVSS 9.2). Affects Core 4.7.0–7.1.1; fixes include 7.1.2, 7.0.6, 6.9.9, 6.8.10, and backports down to 4.7.37. Credit: Robert Ressl.
Patchstack Sep 23 update (same probing post, revised): when the Sep 22 note first went up, every observed request was reconnaissance against harmless core files. That is no longer true. Traffic is now more than ten times first-evening volume, across a far wider site spread, and has moved through three stages: (1) include ordinary core files as an oracle; (2) include PEAR pearcmd.php with +config-show to confirm register_argc_argv; (3) swap to +config-create to write attacker-controlled PHP under /tmp or /var/tmp. Observed write names include wp-pear-rce-flag.php, poc87902.php, luci_.php, zeta_.php. Some payloads are marker strings; others write a short tag that executes a shell command on access. First file-write attempt Patchstack logged: 15:34 UTC Sep 22. Peak volume around midday UTC Sep 23.
Commoditization: user agents cve-2026-87902-poc/1.0 and nuclei-cve-2026-87902/1.0 are in the traffic — a named Nuclei template means this is past a handful of operators reading the diff. Patchstack: a file in /tmp is usually not web-reachable, so it is proof of execution rather than a persistent web shell by itself; treat any successful stage-three write as full compromise. Named victim sites and successful RCE campaign counts remain Undisclosed (Patchstack / BleepingComputer Sep 23 do not publish them).
Ops: update to 7.1.2 or your branch backport now. Stopgap: reject traversal sequences in pagename; disabling register_argc_argv breaks the pearcmd chain but does not fix the inclusion. Hunt for %2e%2e / %252e%252e in pagename, pagename+page_id pairs, pearcmd / +config-show / +config-create, the two PoC/Nuclei user agents, OPML/RSS returned from normal page URLs, and unexpected .php under /tmp and /var/tmp.
POV: Unauth critical on the default CMS went from same-day probes to commoditized write-to-disk in under 24 hours. Patch tonight. Sources: wordpress.org 7.1.2 Sep 22 + Patchstack Sep 23 update + BleepingComputer Sep 23.
