Story thread · 3 reports / 3 sources
WordPress patches a critical severity security vulnerability
computerworld.com · 19h · first report

How the coverage leans
Across 3 sources · syndicated copies counted once
WordPress has patched what it described as a critical severity security vulnerability that would allow an unauthenticated attacker full remote code execution (RCE) capabilities. There have already been reports of attacks in the wild. Given its popularity, WordPress has frequently been under attack , and patched another maximum severity bug allowing RCE in July. WordPress said the current hole, tracked as CVE-2026-87902 , was discovered and reported to the company by Switzerland-based security researcher Robert Ressl . The post announcing the WordPress 7.1.2 security release said that the fix addressed an issue where “an unauthenticated attacker can, under certain conditions, make page template resolution include a chosen readable local PHP file outside the active theme directories. If relevant pre-conditions for both the server environment and the active theme are met, this can lead to remote code execution (RCE).” It urged users to update their sites immediately, and said that the fix
The coverage
The conversation · 0
Sign in to join the conversation.
No comments yet — start the thread.