wordpress.org Critical WordPress Flaw Allows Remote Code Execution
Article Content
- •Critical vulnerability CVE-2026-87902 allows remote code execution on some WordPress sites.
- •All versions from 4.7.0 to 7.1.1 are affected; immediate updates are recommended.
- •No active exploitation reported as of September 22, 2026.
WordPress has released version 7.1.2 to address a critical vulnerability (CVE-2026-87902) that allows unauthenticated attackers to execute code on certain servers by loading a PHP file from outside the theme directories. The flaw affects all versions from 4.7.0 to 7.1.1, and site owners are urged to update immediately. The vulnerability has a CVSS score of 9.2 and requires specific conditions related to the server environment and active theme for exploitation. As of September 22, there are no reports of active exploitation or public proof-of-concept code. The security issue was reported by Robert Ressl, and WordPress has backported the fix to all supported branches. Automatic updates will begin for sites with that feature enabled, while others can manually update via the dashboard or download from WordPress.org.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2026-87902 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Local File Inclusion Vulnerability in WordPress Core A critical vulnerability (CVE-2026-87902) has been discovered in WordPress Core, affecting all versions up to 7.1.1. This flaw allows unauthenticated local file inclusion via the locate_template() function, potentially leading to remote code execution under specific conditions. The vulnerability arises from improper…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…