chiprook
← Security
SecurityOctober 8, 2026, 06:00

WordPress 7.1.2 patches critical path traversal to RCE

A critical flaw in WordPress core, CVE-2026-87902 (CVSS 9.2), lets unauthenticated attackers steer get_page_template() into including local PHP files, potentially leading to remote code execution. Versions 4.7.0 through 7.1.1 are affected; the 7.1.2 patch shipped on 22 September 2026 and CISA has added the bug to its Known Exploited Vulnerabilities catalog.

WordPress 7.1.2 patches critical path traversal to RCE
#WordPress
Read next
Security

WordPress 7.1.2 patches CVE-2026-87902 exploited within hours

Security

WordPress Patches Critical Flaw Enabling Code Execution on Some Servers

Security

SolarWinds Patches Two Critical RCE Flaws in Observability Self-Hosted

Security

CVE-2026-78249: Path Traversal in Fujifilm and Sharp MFP Web Consoles