WordPress patches a critical severity security vulnerability
Summary
WordPress has released version 7.1.2 to patch a critical severity vulnerability (CVE-2026-87902) that allows unauthenticated attackers remote code execution. The vulnerability exploits how page templates are resolved, enabling attackers to include and execute malicious PHP files if specific server and theme conditions are met. Attacks in the wild have already been reported, and users are urged to update immediately, as the fix affects many older versions.
IFF Assessment
This vulnerability allows unauthenticated attackers to gain full remote code execution capabilities, which is detrimental to defenders.
Severity
Defender Context
This critical RCE vulnerability in WordPress is a high-priority patch for any organization running the platform. Defenders should immediately update their WordPress installations and monitor for signs of exploitation, such as unusual activity in temporary directories or unexpected PHP files. The widespread nature of WordPress means this vulnerability poses a significant risk to a large number of websites.