AI Weekly Malaysia

Back to items Summaries

WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers

ID
27437
Status
summarized
Published
23 Sep 2026, 2:03 AM
Fetched
23 Sep 2026, 5:09 AM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/wordpress-issues-patch-for-critical.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
6.5
Created
23 Sep 2026, 5:10 AM
Tags
Audience
developerssaas_founders

What happened

WordPress patched a critical unauthenticated vulnerability (CVE-2026-87902, CVSS 9.2) on September 22 in version 7.1.2, affecting all versions from 4.7.0 through 7.1.1. The flaw allows an attacker with no account to make a site load a PHP file outside theme folders via path traversal in template file selection, potentially enabling code execution on servers where a suitable PHP file already exists.

Why it matters

If you run any WordPress site on versions 4.7.0 through 7.1.1, update immediately to the patched release for your branch (7.1.2, 7.0.6, 6.9.9, etc.)—there is no workaround besides updating. Sites updated as recently as September 17's 7.1.1 release are still vulnerable, so don't assume you're patched just because you updated last week.

Discussion angle

The attack requires a second condition—a PHP file on the server that does something useful when loaded—so real-world exploitability varies; discuss how to audit whether your WordPress deployments meet that second condition and whether automatic background updates are enabled.

Top