Critical WordPress Flaw Enables Unauthenticated Code Execution — Patch Immediately
A critical vulnerability (CVE-2026-87902, CVSS 9.2) in WordPress versions 4.7.0 through 7.1.1 allows unauthenticated attackers to load arbitrary PHP files, potentially leading to remote code execution. The risk is compounded by specific server-side misconfigurations, particularly when PHP's 'register_argc_argv' directive is enabled and the active theme contains certain folder structures. This highlights how unpatched CMS platforms combined with insecure default or permissive server configurations dramatically expand an organization's attack surface. Because no authentication is required to exploit this flaw, internet-facing WordPress sites are at immediate and severe risk, making rapid patching and configuration hardening non-negotiable.
Tactical Insight
Immediate Actions
- Update all WordPress installations to version 7.1.2 or later without delay, prioritizing internet-facing and production environments.
- Audit your PHP configuration and set `register_argc_argv` to `Off` in `php.ini` for all servers hosting WordPress sites.
- Conduct an emergency review of active themes to identify and remediate any folder structures that increase exposure to this vulnerability.
Long-Term Improvements
- Implement automated CMS and plugin update policies to ensure critical patches are applied within 24–48 hours of release.
- Enforce a hardened PHP configuration baseline across all web servers, validated through regular configuration audits.
- Maintain a complete and current inventory of all web applications, their versions, and underlying server configurations to accelerate patch scope assessment.
Detection Measures
- Deploy a Web Application Firewall (WAF) with rules targeting arbitrary PHP file inclusion attempts to detect and block active exploitation.
- Enable centralized logging of web server access and error logs, and alert on anomalous PHP file load patterns or unexpected 500-series errors.
- Integrate WordPress and server assets into a vulnerability scanning platform to receive continuous exposure assessments against newly published CVEs.