WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers
PatchWordPressOur summary
WordPress has released fixes for CVE-2026-87902, a CVSS 9.2 core vulnerability affecting versions 4.7.0 through 7.1.1. An unauthenticated attacker could cause WordPress to load PHP files outside theme directories, which could lead to attacker-controlled code execution on certain server and theme configurations. Site owners should update to WordPress 7.1.2 or the applicable supported-branch release; no workaround is available.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.