CVE Tools

WordPress 7.1.2 Security Release: Unauthenticated LFI to RCE

PatchstackBy Patchstack5 min read

ResearchWordPress

Our summary

WordPress 7.1.2 addresses CVE-2026-87902, an unauthenticated local file inclusion flaw in page template resolution affecting WordPress Core from 4.7.0 through 7.1.1. The issue can allow remote code execution under certain server configurations, so administrators should apply the available fixed release as soon as possible.

Read at Patchstack

Below is the opening; the full story is at Patchstack.

From Patchstack

WordPress 7.1.2 landed on 22 September 2026. It’s a security-only release with a single fix, and that fix is the most serious thing WordPress has patched in a while: an unauthenticated local file inclusion in page template resolution that can reach remote code execution.

Patchstack customers are protected by a RapidMitigate rule. We still recommend updating to the most recent version of WordPress available.…

Continue at Patchstack

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store