Advertisement
Content Moved? Use Search to Locate
Screenshot of Bing search results for 'sheboygan hip hop cookout hit.' The top result is an article from Sheboygan Life about Curdy and the Cheese Heads' new hip-hop hit, with additional related links and video content. Bing's results also feature options to learn more about related topics and ask questions about the band.

How to Verify the WordPress CVE-2026-87902 Fix

To verify the CVE-2026-87902 fix, record your installed WordPress version, compare it with the fixed release for that same branch in the WordPress-published security advisory, then update and check the version again. WordPress lists fixes for multiple branches, so 7.1.2 is not the only fixed version. PHP and theme conditions can help prioritize an urgent investigation, but they do not replace updating core.

WordPress’s 7.1.2 security release announcement, dated September 22, 2026, recommends immediate updating. It says automatic background updates begin on sites that support them, but the announcement does not confirm that your site updated. Check your own installation.

1. Record the installed WordPress version

In the dashboard, go to Dashboard > Updates and note the installed version and any available core update. WordPress’s Dashboard Updates documentation describes that screen as a place to manage core upgrades and says a successful upgrade displays a completion message.

If you or your developer has shell access and WP-CLI, run this command from the WordPress installation:

wp core version

The WP-CLI command documentation says wp core version displays the installed WordPress version. The dashboard or command reports a version; neither, by itself, proves that every core file is intact or that the site was never compromised.

2. Match the version to its branch’s fix

In the WordPress security advisory, find the fixed release for your installed branch. Compare versions within that branch rather than assuming you must move to the newest branch to get this fix. The advisory lists branch-specific fixes, including 7.1.2, 7.0.6, 6.9.9, 6.8.10, and releases for older branches.

Hypothetical example: If your site reports WordPress 7.0.5, compare it with the advisory’s 7.0.6 fix for the 7.0 branch. Update to the fixed release for that branch; a branch jump is not required solely to address this vulnerability.

If your branch or version is not clear in the advisory, do not guess that it is fixed. Ask your host or WordPress developer to identify the correct update path. Once you have identified the applicable fixed release, apply the core update through your usual managed update process.

3. If you cannot update immediately

Give your host or developer these specific checks. They help assess and prioritize the site’s conditions; they are not a reason to leave the core vulnerability unpatched.

  • Confirm the PHP configuration serving the site. Ask which PHP version and configuration apply to this WordPress installation, and whether register_argc_argv is enabled. The advisory identifies that setting as relevant to the described PEAR-to-remote-code-execution chain.
  • Inspect the active parent and child themes. Ask whether the top-level directory for either active theme—the theme’s own directory—has a name that starts with page-. The advisory identifies this as one of the conditions relevant to the issue; it is not a request to look for a page- directory inside the theme.
  • Check the actual hosting configuration. The advisory says the default cPanel configuration is affected when PHP prior to 8.5 is in use. That is a scoped statement about the described environment, not evidence that every cPanel site is exploitable. Do not infer the site’s exposure from a cPanel label; have the host confirm the PHP configuration serving it.

WordPress describes CVE-2026-87902 as conditional: an unauthenticated attacker may cause page-template resolution to include a chosen readable local PHP file outside the active theme directories. Relevant server and active-theme preconditions can make this lead to remote code execution. The issue does not mean every unpatched site is exploitable or that every such inclusion results in code execution.

If an update must be delayed, Patchstack describes rejecting traversal sequences in pagename as a possible stopgap and disabling register_argc_argv as a way to break the described PEAR chain. Patchstack also says these measures do not close the vulnerable template inclusion. Discuss any temporary mitigation with your host or security provider; neither these measures nor a WAF, Cloudflare rule, or control-panel setting substitutes for the WordPress core update.

4. Verify the update and check critical site functions

After updating, keep a record of the version displayed in Dashboard > Updates or returned by wp core version. Confirm that it matches or is later than the fixed release for that branch in the advisory. Where the dashboard provides it, retain the successful-upgrade notice as additional evidence that the update completed.

Then check a few important paths on the live site:

  • Load key public pages, including pages that bring qualified enquiries or sales.
  • Confirm that an administrator can sign in and use the dashboard.
  • If the site takes transactions, test the relevant checkout or other critical transaction flow using an appropriate safe test process.

These checks confirm the reported version and help catch operational problems after the update. They do not establish that core files are unmodified or rule out earlier compromise.

5. If the site was unpatched before the update

Ask your host or security provider to review relevant logs and investigate unexpected PHP files if the site was exposed before patching or you find other signs that warrant review. Patchstack’s CVE-2026-87902 activity update reports that it first observed activity at 11:49 UTC on September 22 and that its September 23 update observed attempts to use pearcmd.php to write PHP files. That is Patchstack’s telemetry, not proof of activity against your host or compromise of your site. A suspicious request is an investigation lead, not confirmation that it succeeded.

Has your host confirmed which PHP configuration serves your WordPress site, and does the advisory list a fixed release for your installed branch?

Sources

Editorial note: AI assists with research, drafting and automated checks. Sources are linked so you can verify the guidance. Platform requirements can change; confirm the details that apply to your setup.