Story thread · 3 reports / 3 sources

WordPress patches a critical severity security vulnerability

computerworld.com · 19h · first report

WordPress patches a critical severity security vulnerability

How the coverage leans

Across 3 sources · syndicated copies counted once

WordPress has patched what it described as a critical severity security vulnerability that would allow an unauthenticated attacker full remote code execution (RCE) capabilities. There have already been reports of attacks in the wild. Given its popularity, WordPress has frequently been under attack , and patched another maximum severity bug allowing RCE in July. WordPress said the current hole, tracked as CVE-2026-87902 , was discovered and reported to the company by Switzerland-based security researcher Robert Ressl . The post announcing the WordPress 7.1.2 security release said that the fix addressed an issue where “an unauthenticated attacker can, under certain conditions, make page template resolution include a chosen readable local PHP file outside the active theme directories. If relevant pre-conditions for both the server environment and the active theme are met, this can lead to remote code execution (RCE).” It urged users to update their sites immediately, and said that the fix

The coverage

  1. WordPress Patch Became Exploit Blueprint: CVE-2026-87902 Webshells Hit 350K Sites

    techtimes.com · 1h

  2. WordPress vulnerability attacked hours after patch

    heise.de · 4h

The conversation · 0

Sign in to join the conversation.

No comments yet — start the thread.