攻击者在WordPress修复一个关键漏洞后的数小时内就开始利用该漏洞。该漏洞编号为CVE-2026-87902,允许未经身份验证的攻击者在网站服务器上运行代码。该漏洞仅在特定条件下才会触发。
Attackers began exploiting a critical WordPress flaw within hours of the fix. The bug, CVE-2026-87902, can let an attacker with no run code on a website’s server. It only works under certain conditions.
WordPress在9月22日发布的7.1.2版本中修复了该漏洞,并为4.7版本以来的所有旧分支提供了补丁。其安全公告将该漏洞评为“严重”级别,CVSS评分为9.2,并确认由Robert Ressl报告。据WordPress安全公司Patchstack称,首次攻击发生在当天协调世界时(UTC)11:49。
WordPress fixed the flaw in version 7.1.2 on 22 September. It also patched every older branch back to 4.7. Its security advisory rates it critical, with a CVSS score of 9.2, and credits Robert Ressl with reporting it. The first attacks came at 11:49 UTC that day, according to WordPress security company Patchstack.
攻击原理:该漏洞存在于get_page_template函数中,该函数负责选择显示页面的模板文件。未经身份验证的攻击者可以利用此漏洞加载活动主题文件夹之外的可读PHP文件。
How the attack works The flaw sits in get_page_template, the function that picks which template file shows a page. An unauthenticated attacker can make it load a readable PHP file from outside the active theme’s folders.
攻击必须满足两个条件:活动主题必须包含一个名称以“page-”开头的顶级文件夹;服务器必须存有攻击者可以利用的PHP文件。在目前的攻击案例中,该文件为pearcmd.php,它是PHP包管理器PEAR的一部分。
Two conditions have to be met. The active theme must contain a top-level folder whose name starts with “page-”. The server must also hold a PHP file the attacker can use. In the attacks so far, that file is pearcmd.php, part of the PHP package manager PEAR.
Patchstack表示,攻击者在探测WordPress核心文件后,检查了三个常见位置是否存在pearcmd.php。随后,他们利用该文件将恶意文件写入服务器的/tmp和/var/tmp文件夹。Patchstack研究主管Dave Jong写道,攻击流量随后稳步攀升,并在9月23日协调世界时中午左右达到峰值,是首日晚间流量的十倍以上。
After probing WordPress core files, attackers checked for pearcmd.php in three common locations, Patchstack said. They then used it to write files into the server’s /tmp and /var/tmp folders. Traffic then climbed steadily, Patchstack’s research lead Dave Jong wrote. It peaked around midday UTC on 23 September at more than ten times the volume of the first evening.
自动更新限制了损害:据《黑客新闻》(The Hacker News)报道,安全公司Previdian记录了68次利用尝试。其创始人兼首席执行官Ryan Dewhurst表示,由于存在触发条件,入侵成功的可能性较低。
Auto-updates limit the damage Security company Previdian recorded 68 exploitation attempts, The Hacker News reported. Its founder and chief executive, Ryan Dewhurst, said the conditions make a break-in less likely.
Dewhurst告诉《黑客新闻》:“由于WordPress默认开启自动更新,我们可能会看到大规模的利用尝试,但实际被攻破的网站相对较少。”
“Because WordPress has auto-updates enabled by default, we’re likely to see mass-exploitation attempts, but relatively few actual compromises,” Dewhurst told The Hacker News.
网站所有者应更新至7.1.2版本或其对应分支的补丁版本。Patchstack还建议在pagename参数中拦截“..”序列。关闭PHP的_argc_argv设置可以阻断利用pearcmd的攻击步骤。
Site owners should update to 7.1.2 or the patched release on their branch. Patchstack also advises blocking “..” sequences in the pagename parameter. Turning off PHP’s_argc_argv setting breaks the pearcmd step.
被利用的漏洞:这个 WordPress 安全漏洞只是最近一系列在漏洞被公开后不久就被黑客利用的漏洞之一。本月,思科(Cisco)警告称黑客正在利用一个严重等级为“最高级”的 ISE(Identity Services Engine)漏洞;微软在九月份的更新中修复了共计 974 个安全漏洞,其中有两个漏洞此前已经被黑客攻击过;谷歌也修复了 Chrome V8 浏览器中的一个被黑客利用的漏洞。
A month of exploited flaws The WordPress bug is the latest in a run of flaws exploited soon after disclosure. Cisco warned this month that hackers were exploiting a maximum-severity ISE flaw. Microsoft’s September update fixed a record 974 flaws, two of them already under attack. Google patched a Chrome V8 flaw used in attacks.