# Attackers rush to exploit new WordPress CVE‑2026‑87902 bug using pearcmd.php to plant malicious code

*Thursday, September 24, 2026 at 6:15 AM UTC — Hamer Intelligence Services Desk*

**Published**: 2026-09-24T06:15:04.738Z (3h ago)
**Category**: cyber | **Region**: Global
**Importance**: 7/10
**Sources**: OSINT
**Permalink**: https://hamerintel.com/data/articles/18694.md
**Source**: https://hamerintel.com/summaries

---

**Deck**: Within hours of disclosure, attackers began targeting WordPress sites via CVE‑2026‑87902, abusing pearcmd.php to write their own PHP files on vulnerable servers. The flaw only works under certain theme and server conditions, but for affected sites it opens the door to full takeover.

A newly disclosed WordPress vulnerability, CVE‑2026‑87902, is already being exploited in live attacks, putting site owners on notice that the patching window is short.

Security reporting says attackers moved within hours of disclosure to target the flaw. The exploit route runs through pearcmd.php, a script tied to the PEAR package management system for PHP. When specific theme and server conditions are met, attackers can use pearcmd.php to write PHP files of their choosing to the server’s disk.

Once an attacker can drop and run arbitrary PHP files, they effectively control what the web server does, from accessing databases to serving malicious content. The vulnerability doesn’t affect every WordPress setup; it requires the right combination of theme and server configuration. But where those conditions exist, it can turn an ordinary website into a foothold for broader compromise.

Because WordPress underpins a huge portion of the public web, even a limited subset of vulnerable sites can give attackers a significant pool of targets. Automated scans make it easy to probe thousands of installations and wait for the ones that respond.

The key questions now are how quickly hosting providers and site owners can harden their systems, and whether exploit activity remains largely opportunistic or starts to show signs of use in more targeted campaigns. Guidance from major security vendors or national cyber agencies, and updates from theme and plugin developers, will be early indicators of how seriously the wider ecosystem is treating CVE‑2026‑87902.
