Security
CVE-2026-87902: update to WordPress 7.1.2 now

On 22 September 2026, WordPress released version 7.1.2 to fix a critical security flaw in core. Tracked as CVE-2026-87902, it is an unauthenticated path traversal that can lead to remote code execution, and it affects every WordPress version from 4.7.0 through 7.1.1. That is almost ten years of releases.

What the bug is
The problem sits in how WordPress looks up page templates (get_page_template()). Normally, WordPress only loads template files from your active theme. The flaw lets an attacker steer that lookup to a readable .php file somewhere else on the server, without logging in.
Whether that becomes full remote code execution depends on the server and the active theme. That is why it scores 9.2 on CVSS v4 rather than a perfect 10. But “it depends” is not a comfort here: attackers only need one server where the conditions line up.
It is already being exploited
Security teams saw attacks within hours of disclosure. Patchstack reported attackers using the bug to include pearcmd.php, a PEAR tool that exists on many PHP servers, and then using it to write their own PHP files to disk. Public scanning tools for this CVE are also circulating, so unpatched sites will be found.
What to do
- Update to WordPress 7.1.2. If you are on an older branch, the fix was backported to 24 older branches, from 7.0.6 down to 4.7.37. Check Dashboard → Updates.
- If automatic background updates are on, confirm the update actually happened. Do not assume.
- Ask whether PEAR is installed on your server. If you do not use it, remove it or make sure
pearcmd.phpis not reachable. Local stacks such as XAMPP often ship with PEAR too. - Look through your access logs for odd template or path requests (
../sequences) since 22 September, and for new PHP files inwp-content, especiallyuploads. - Put a web application firewall in front of important sites. It buys you time the next time a core bug drops.
Why this one matters
Most WordPress hacks come from plugins and themes. Core bugs are rare, which makes them dangerous: people forget to check. This site was updated to 7.1.2 the same week. If you manage client sites, this is a good moment to confirm every one of them is on a patched version, including the ones you have not logged in to for a while.