Another WordPress Flaw Proves Why Complexity Is the Enemy of Security

A critical WordPress flaw is actively being exploited in the wild, reminding us that running the internet's favorite CMS is an endless game of whack-a-mole....

Feed
September 24, 2026
Another WordPress Flaw Proves Why Complexity Is the Enemy of Security


Here we go again. Another day, another critical vulnerability threatening the digital scaffolding of half the known internet. A fresh path traversal bug, tracked as CVE-2026-87902, has landed in the wild with an 8.1 severity score, and attackers aren't wasting any time poking at it. Exploitation attempts started merely hours after the patch dropped. If you run a WordPress site, stop reading this and go update your core files right now.

The vulnerability itself is a masterclass — oddly — in how subtle assumptions in template resolution logic can cascade into complete base compromise. See, not always! Discovered by researcher Robert Ressl, the flaw lets unauthenticated actors force `get_page_template()` to pull in local PHP files sitting well outside active theme directories —. Honestly chain that little — to be fair — trick together with a readable file like `pearcmd.php`. And suddenly you're looking straight down the barrel of remote code execution (give or take). Now, millions, it requires specific conditions, sure – like particular theme directory naming conventions and loose PHP setups – but when you power over forty percent of the web — surprisingly enough. Now, 'precise conditions' still means of exposed endpoints.

Another WordPress Flaw Proves Why Complexity Is the Enemy of Security

What exhausts me about cycles like this isn't just the zero-day scramble, but the profound architectural hubris that underpins it. We've built an entire global web ecosystem on top of monolithic, hyper-complex systems where a minor misinterpretation of a template path can hand the keys of your application over to random threat actors scanning ports at three in the morning. When software tries to be everything to everyone, the attack surface balloons out of control. Complexity is the silent killer of secure systems.

The core maintainers acted quickly, shipping version 7.1.2 and thoughtfully backporting fixes all the way back to version 4.7. But let's be honest about the long tail. Thousands of neglected client sites, abandoned blogs, and forgotten staging servers will sit unpatched for months, quietly rotting away until a botnet scoops them up. If your architecture relies on manual diligence to survive basic path traversal exploits, you aren't building for the long haul. You're just waiting for the inevitable.