Skip to content
Critical WordPress Flaw Allows Remote Code Execution

Critical WordPress Flaw Allows Remote Code Execution

First seen 22 Sep 2026, 20:28 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 22, 2026 at 21:59 UTC
  • Critical vulnerability CVE-2026-87902 allows remote code execution on some WordPress sites.
  • All versions from 4.7.0 to 7.1.1 are affected; immediate updates are recommended.
  • No active exploitation reported as of September 22, 2026.

WordPress has released version 7.1.2 to address a critical vulnerability (CVE-2026-87902) that allows unauthenticated attackers to execute code on certain servers by loading a PHP file from outside the theme directories. The flaw affects all versions from 4.7.0 to 7.1.1, and site owners are urged to update immediately. The vulnerability has a CVSS score of 9.2 and requires specific conditions related to the server environment and active theme for exploitation. As of September 22, there are no reports of active exploitation or public proof-of-concept code. The security issue was reported by Robert Ressl, and WordPress has backported the fix to all supported branches. Automatic updates will begin for sites with that feature enabled, while others can manually update via the dashboard or download from WordPress.org.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-22
CVE-2026-87902 published
WordPress disclosed a critical vulnerability allowing unauthenticated code execution under specific conditions.
Thehackernews
2026-09-22
WordPress 7.1.2 released
A security release to fix the critical vulnerability, urging users to update immediately.
wordpress.org

More articles in this cluster (3)

Following this threat?

Track CVE-2026-87902 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed