chiprook
← Security
SecuritySeptember 23, 2026, 01:03

WordPress Patches Critical Flaw Enabling Code Execution on Some Servers

WordPress released version 7.1.2 on September 22 to fix a critical core flaw that lets an unauthenticated attacker make a site load a PHP file from outside its theme folders. On some servers this can escalate to running attacker code. Fixes shipped for every supported branch back to 4.7.

WordPress Patches Critical Flaw Enabling Code Execution on Some Servers
#WordPress
Read next
Security

Chinese hackers hit 996 Zyxel switches and WordPress sites

Security

U.S. Warns Cartels Are Adopting Battlefield Drone Tactics Faster Than Defenses

Security

Volexity spots China-aligned UTA0565 exploiting Chrome and Windows zero-days

Security

ShinyHunters claims FBI personnel data theft via Oracle PeopleSoft zero-day