WordPress 7.1.2 patches critical path traversal to RCE
A critical flaw in WordPress core, CVE-2026-87902 (CVSS 9.2), lets unauthenticated attackers steer get_page_template() into including local PHP files, potentially leading to remote code execution. Versions 4.7.0 through 7.1.1 are affected; the 7.1.2 patch shipped on 22 September 2026 and CISA has added the bug to its Known Exploited Vulnerabilities catalog.
- CVE-2026-87902 is rated Critical at CVSS 9.2
- All WordPress releases from 4.7.0 to 7.1.1 are affected
- Patch 7.1.2 shipped on 22 September 2026 with backports to 4.7.37
- CISA added the flaw to its Known Exploited Vulnerabilities catalog
Read next
Security