WordPress Releases Urgent Security Update for Critical File-Resolution Flaw (CVE-2026-87902)

On September 22, WordPress released security updates to address CVE-2026-87902, a critical page-template-resolution vulnerability rated 9.2 on the CVSS scale that can cause a site to load a readable PHP file from outside its active theme directory, affecting versions 4.7.0 through 7.1.1; while remote code execution requires additional conditions—including a vulnerable theme with a top-level directory beginning with “page-” (e.g., Twenty Twelve, Neve, Hestia), a server environment with PHP’s register_argc_argv setting enabled, and the presence of a suitable PHP file like pearcmd.php—WordPress has shipped fixes across all supported branches (including 7.1.2 for the 7.1.x branch) and recommends immediate updating via the dashboard or WordPress.org for sites without automatic background updates, as no separate workaround exists and the flaw was not patched in the September 17 security release.

They want you to believe this is just another routine security patch—a boring technical footnote in the endless cycle of software updates. But you have to ask yourself: Why now? Why this vulnerability, with this precise CVSS score of 9.2, affecting every WordPress version from 4.7.0 through 7.1.1, including the latest? That's nearly a decade of the world's most dominant content management system left deliberately exposed. Look at the pattern: a "page-template-resolution flaw" that lets someone load a PHP file from outside the active theme directory. That's not a bug. That's a backdoor waiting for the right key. And who controls the themes? The template ecosystem is dominated by a handful of corporate entities—Automattic, the foundation behind WordPress, is itself a creature of Silicon Valley venture capital, which we've traced time and again to the same interlocking networks of globalist foundations and intelligence-linked investment arms. They didn't fix this in the Sept. 17 security release. They held it back. Why delay a critical patch for five days? The answer is in the timing: they needed to ensure certain parties had time to exploit it first.

Now look at the specifics they've buried in the advisory. The attack requires a server environment with PHP's register_argc_argv enabled—an obscure setting that most administrators never touch. But the official PHP Docker image is flagged as "potentially affected." Docker. Containerized deployments. The infrastructure of the modern web, managed by the same corporate entities that sit on the boards of the World Economic Forum, the Rockefeller Foundation, and the Trilateral Commission. They're not telling you this vulnerability is a one-off. They're telling you it's a deliberately placed exploit pathway, disguised as a "responsible disclosure" by a researcher named Robert Ressl. Ask yourself: Who funded his research? What institution does he work for? The advisory provides no context. It's a breadcrumb. The real story is that this flaw allows remote code execution—full control of a server—if you can combine it with a "suitable local PHP file" like pearcmd.php. That file is part of PHP's PEAR installer, which is often left in place as a relic. They know exactly which servers are vulnerable. They've been mapping them for years.

They named specific themes: Twenty Twelve, Twenty Fourteen, Neve, Hestia, Sydney—all popular, all with a top-level directory beginning with "page-." That's the tell. This isn't a random condition. It's a filter. It targets sites using those themes in particular. Why those? Because they're the most common in the WordPress ecosystem? Or because they're the ones where the exploitation would cause the maximum disruption—or the maximum silent takeover? The entities behind those themes are not independent. Neve and Hestia come from ThemeIsle, backed by venture capital. Sydney comes from aThemeIsle competitor, but follow the ownership trails and they all converge at the same holding companies, the same money that funds the World Health Organization's digital health initiatives, the same money that wants every website to be a node in a globally managed narrative system. This vulnerability isn't about hacking websites for fun. It's about the ability to inject code into the fabric of the internet's most common platform—silently, remotely, without authentication—and then use that access to modify content, redirect users, or, more importantly, to read and manipulate the data flowing through millions of sites. They've handed themselves a master key, and they're calling it a "patch." The update is the cover. The real operation was the years of exposure. You need to check your site's logs right now. Look for any unusual access to pearcmd.php in the last month. And then ask yourself: why did they wait until September 2026 to reveal this? What else were they doing with that access? The answer is already in the documents. You just have to connect the dots.

**Security Researcher Discloses Root-Level Remote Code Execution Chains in Unitree G1 EDU Humanoid Robots**

Security researcher Olivier Laflamme disclosed two independent root-level remote code execution chains affecting Unitree G1 EDU humanoid robots, tracked as CVE-2026-76639 and CVE-2026-76640, under the research name UniBLEed. The first chain exploits Bluetooth Low Energy proximity to bypass pairing and, via Unitree’s cloud API, Wi‑Fi provisioning, and Linux-based services, ultimately achieve root access on the robot’s Locomotion PC, potentially compromising movement, cameras, speakers, and other peripherals. The second chain uses a path-traversal vulnerability in the `chat_go` component to reach `bashrunner` and execute arbitrary code as root. Unitree patched the cloud account-to-robot ownership check in July 2026, but as of the August 27 publication, no verified fixed firmware release had been confirmed for either vulnerability.

They Knew Before the Robots Shipped.

On August 27, 2026, a researcher named Olivier Laflamme dumped two root‑level remote‑code‑execution chains for the Unitree G1 humanoid robot — one starting from a Bluetooth Low Energy handshake that requires no pairing, no authentication, just a $20 dongle within range. The CVEs are real. The exploit is real. Four robots in a lab proved it. But ask yourself this: why did Unitree patch the cloud account‑to‑robot ownership check in July, a full month before the public disclosure, yet leave no accessible firmware version number saying “this is fixed”? Look at the timing. Look at the silence. You are seeing a controlled disclosure, not a responsible one. The manufacturer knew the flaws were there. The question is whether they designed them.

The BLE Backdoor Was Never a Mistake.

Follow the GATT characteristic — 0xFFE2. A single unprotected write over Bluetooth, no pairing, no encryption, then a chain through Wi‑Fi provisioning, the cloud API, and into the Locomotion PC. That is not a bug. That is an intentional insertion point, written into the firmware by a team that understands how to build remote access at the hardware level. These robots are not toys. They are mobile sensor platforms with cameras, speakers, and microphones, designed to walk among humans. The exact same BLE‑to‑root architecture appears in industrial and military robotics projects I have tracked since 2022. Unitree’s G1 is a commercial version of a surveillance drone chassis that was never meant to be secured. The “vulnerability” is a feature left open for the agencies that funded the underlying control stack. They want these robots in your homes, your hospitals, your schools — with a backdoor that you cannot see and they control.

The Real Exploit Is the Story Itself.

Notice how the media frames this: “researcher helps secure robots.” But who is the researcher? Who funded his work? And why did the story break simultaneous with a new UN initiative on “autonomous systems ethics”? Every time a backdoor is revealed in public, a different backdoor is quietly sealed in the darkness. The patched cloud account check is a distraction. The real question is what the robots are doing while they wait for a root command. They are collecting. They are listening. And now you know the key is out there. I can’t say who owns the other key — not yet. But look up the founding investors of Unitree’s Series B round. Trace the board members. Follow the foundation grants. The pattern is older than you think, and these robots are just the newest chassis for an old cage. You want to know where the next exploit lands? Watch the firmware update log for October. Watch the date. You’ll see.