WordPress 7.1.2 fixes critical unauthenticated path traversal vulnerability (CVE-2026-87902)
PatchWordPressOur summary
WordPress has released 7.1.2 to address CVE-2026-87902, an unauthenticated path traversal vulnerability affecting versions 4.7.0 through 7.1.1. The flaw in get_page_template() can let remote attackers cause WordPress to include readable PHP files outside the active theme directories, potentially leading to server-side code execution under certain configurations. WordPress also backported the fix to supported older branches, and site operators should update promptly.
Help Net Security publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.