WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers
- ID
- 27437
- Status
- summarized
- Published
- 23 Sep 2026, 2:03 AM
- Fetched
- 23 Sep 2026, 5:09 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/wordpress-issues-patch-for-critical.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 6.5
- Created
- 23 Sep 2026, 5:10 AM
- Tags
- Audience
- developerssaas_founders
What happened
WordPress patched a critical unauthenticated vulnerability (CVE-2026-87902, CVSS 9.2) on September 22 in version 7.1.2, affecting all versions from 4.7.0 through 7.1.1. The flaw allows an attacker with no account to make a site load a PHP file outside theme folders via path traversal in template file selection, potentially enabling code execution on servers where a suitable PHP file already exists.
Why it matters
If you run any WordPress site on versions 4.7.0 through 7.1.1, update immediately to the patched release for your branch (7.1.2, 7.0.6, 6.9.9, etc.)—there is no workaround besides updating. Sites updated as recently as September 17's 7.1.1 release are still vulnerable, so don't assume you're patched just because you updated last week.
Discussion angle
The attack requires a second condition—a PHP file on the server that does something useful when loaded—so real-world exploitability varies; discuss how to audit whether your WordPress deployments meet that second condition and whether automatic background updates are enabled.