WordPress patches a critical severity security vulnerability

Chronological Source Flow
Back

AI Fusion Summary

WordPress released security update 7.1.2 to patch a critical severity vulnerability, CVE-2026-87902, which allows unauthenticated attackers full remote code execution (RCE) capabilities. Reported by researcher Robert Ressl, this flaw has already been exploited in the wild. This incident follows another maximum severity RCE bug patched in July. The fix addresses a specific issue where unauthenticated attackers could, under certain conditions, manipulate page templates to execute code, highlighting the platform's frequent targeting due to its popularity.
Community Comments
Loading updates...
0