WordPress patches a critical severity security vulnerability

Summary

WordPress has released version 7.1.2 to patch a critical severity vulnerability (CVE-2026-87902) that allows unauthenticated attackers remote code execution. The vulnerability exploits how page templates are resolved, enabling attackers to include and execute malicious PHP files if specific server and theme conditions are met. Attacks in the wild have already been reported, and users are urged to update immediately, as the fix affects many older versions.

IFF Assessment

FOE

This vulnerability allows unauthenticated attackers to gain full remote code execution capabilities, which is detrimental to defenders.

Severity

8.1 High

Defender Context

This critical RCE vulnerability in WordPress is a high-priority patch for any organization running the platform. Defenders should immediately update their WordPress installations and monitor for signs of exploitation, such as unusual activity in temporary directories or unexpected PHP files. The widespread nature of WordPress means this vulnerability poses a significant risk to a large number of websites.

Read Full Story →