WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers

WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers
WordPress has patched CVE-2026-87902, a critical core flaw that could let an unauthenticated attacker load a PHP file from outside a theme folder and, on some servers, potentially execute code. Site owners running any affected version from 4.7.0 through 7.1.1 are urged to update immediately to the fixed releases, including WordPress 7.1.2. #CVE-2026-87902 #WordPress #RobertRessl

Keypoints

  • WordPress fixed a critical core vulnerability in version 7.1.2.
  • The flaw affects all versions from 4.7.0 through 7.1.1.
  • An attacker needs no account and no user interaction to trigger it.
  • On some servers, loading a local PHP file may lead to code execution.
  • WordPress advises all site owners to update immediately, with no workaround available.

Read More: https://thehackernews.com/2026/09/wordpress-issues-patch-for-critical.html