chiprook
← Security
SecurityOctober 3, 2026, 11:00

WordPress 7.1.2 patches CVE-2026-87902 exploited within hours

WordPress 7.1.2 shipped on 22 September 2026 to fix a remote file inclusion flaw, CVE-2026-87902, in get_page_template(). Exploitation attempts began the same day, with Previdian honeypots logging 68 tries, and the fix was back-ported to branches as old as 4.7.

WordPress 7.1.2 patches CVE-2026-87902 exploited within hours
#WordPress
Read next
Security

Cisco Patches Actively Exploited Email Gateway Zero-Day (CVE-2026-76461)

Security

WordPress Patches Critical Flaw Enabling Code Execution on Some Servers

Security

CVE-2026-12227: Critical unauthenticated LFI in Visual Composer WordPress plugin

Science

Model: AI data centers could stay within grid limits with 35 hours of reduced demand