Skip to main content
See every side of every news story
Published • loading... • Updated

WordPress Patches a Critical Severity Security Vulnerability

The critical flaw can let unauthenticated attackers include a readable local PHP file and, under certain conditions, trigger remote code execution.

  • WordPress released version 7.1.2 on Wednesday to fix CVE-2026-87902, a critical unauthenticated path traversal vulnerability that could allow attackers to access PHP files and compromise sites.
  • Classified as Critical with a CVSS score of 9.2, the vulnerability enables remote code execution when specific server conditions and theme preconditions align, creating severe site takeover risk.
  • Security researcher Robert Ressl disclosed the flaw, which affects legacy themes Twenty Twelve and Twenty Fourteen, plus popular third-party options Neve, Hestia, and Sydney when PHP versions prior to 8.5 are used.
  • Administrators should navigate to the WordPress Dashboard, select Updates, and click Update Now to apply the patch, or enable automatic background updates for immediate protection.
  • Recognizing the severity, WordPress developers backported the fix to all versions back to 4.7, urging users to update immediately to prevent complete site compromise.
Insights by Ground AI

18 Articles

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

Caschys Blog broke the news in Geestland, Germany on Tuesday, September 22, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal