{
  "id": 11596639,
  "title": "What the WordPress 4.7.0 to 7.1.1 file inclusion bug teaches about patch windows",
  "url": "https://urgent.news/2026/10/03/what-the-wordpress-4-7-0-to-7-1-1-file-inclusion-bug-teaches-about",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-03T04:00:24.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/jeffreyciend/what-the-wordpress-470-to-711-file-inclusion-bug-teaches-about-patch-windows-24ab"
  },
  "original_language": "en",
  "account": "The WordPress version 4.7.0 to 7.1.1 file inclusion bug highlights the importance of prompt patching. Released on September 22, 2026, the patch addressed a remote file inclusion vulnerability, tracked as CVE-2026-87902, observed within hours of its release. An unauthenticated attacker can manipulate the page template resolution logic, including a local PHP file from outside the active theme directory. For this to lead to code execution, the active parent or child theme must contain a top-level directory starting with 'page-' and the server must host a reachable PHP file readable by the web service account. Public analysis notes two preconditions: the presence of a 'page-' directory and the server's ability to read a target PHP file. Honeypot networks recorded 68 exploitation attempts against this flaw, with early requests originating from New Jersey and later traffic from Indonesian ranges. Attackers probed harmless core files first before moving to PEAR installation paths, indicating a reconnaissance-into-exploitation sequence. The patch window for this vulnerability was effectively zero, as the first recorded attempt appeared on the same day the patched version was released. Automated scanners and exposed WordPress sites contribute to the vulnerability's rapid exploitation. Mitigations include blocking path traversal patterns at the web application firewall, disabling 'register_argc_argv' in PHP configuration, and auditing themes for 'page-' directories. Automatic background updates, theme checks, and temporary directory monitoring are recommended for defenders to reduce their exposure. This incident underscores the importance of timely patching, monitoring, and maintaining WordPress installations.",
  "summary": "What the WordPress 4.7.0 to 7.1.1 file inclusion bug teaches about patch windows WordPress 7.1.2 was released on 22 September 2026 to fix a remote file inclusion flaw tracked as CVE-2026-87902. The interesting part of this event is not the vulnerability class. It is the timeline. Attack attempts were observed within hours of the patch, and the fix was back-ported to every maintained branch going…",
  "key_points": [
    "WordPress 4.7.0 to 7.1.1 patch addresses remote file inclusion vulnerability CVE-2026-87902.",
    "Unauthenticated attacker manipulates page template resolution logic to execute code via PHP file.",
    "Patch window effectively zero as first exploitation attempt recorded on same day as patch release."
  ],
  "editors_take": "This incident underscores that even brief patch windows can be exploited rapidly, emphasizing the need for timely patching, monitoring, and maintaining WordPress installations to reduce exposure to vulnerabilities.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}