ITSECURITY.GURU WHAT HAPPENED · DOES IT AFFECT YOU · WHAT TO DO
BoardWire › Help Net Security
Vulnerabilities

WordPress 7.1.2 fixes critical unauthenticated path traversal vulnerability (CVE-2026-87902)

Illustration · Vulnerability

WordPress released version 7.1.2 to fix a critical flaw that lets an unauthenticated attacker make the software load a PHP file of the attacker’s choosing from outside the site’s active theme folders. On sites where the server and the active theme meet certain conditions, the attacker can go on to run code on the serve

Continue reading at Help Net Security →

More on this