WordPress released version 7.1.2 to fix a critical flaw that lets an unauthenticated attacker make the software load a PHP file of the attacker’s choosing from outside the site’s active theme folders. On sites where the server and the active theme meet certain conditions, the attacker can go on to run code on the server. The project tracks the flaw as CVE-2026-87902 and lists every release from 4.7.0 through 7.1.1 as affected.
WordPress 7.1.2 fixes critical unauthenticated path traversal vulnerability (CVE-2026-87902)
About this summary. This is a short, independently written summary of an article first published by Help Net Security. Cyber Security News did not report or verify the underlying story. Read the original: https://www.helpnetsecurity.com/2026/09/23/cve-2026-87902-wordpress-7-1-2-security-release/

Source attribution: headline and facts are from Help Net Security (helpnetsecurity.com). Summary method: excerpt of the source description. See our source attribution policy.




