WordPress 7.1.2 has been released to fix a critical core vulnerability that could lead to remote code execution under certain server and theme configurations. This issue, tracked as CVE-2026-87902, is rated with a CVSS v4 score of 9.2 and affects WordPress installations dating back to version 4.7. WordPress Core Vulnerability By manipulating page-template handling, an attacker may be able to cause WordPress to include a readable local PHP file located outside the active theme directory.
Successful exploitation could allow attackers to execute arbitrary PHP code on the affected web server, potentially leading to website takeover, data theft, persistent backdoors, malware deployment, or lateral movement across the hosting environment.
The project has also backported the patch to every currently security-supported branch, including WordPress 4.7, enabling administrators to address the issue without immediately upgrading to the latest major release. Patched versions include 7.0.6, 6.9.9, 6.8.10, 6.7.9, 6.6.9, 6.5.12, and corresponding updates for older maintained branches. Security teams should also inspect active themes for top-level page-* directories, identify exposed PHP files outside theme paths, and validate whether register_argc_argv is enabled.
Organizations using containerized PHP or shared-hosting control panels should prioritize exposure assessment, patch verification, and post-update log reviews for unusual requests targeting page-template parameters.




![Top 10 Best Decentralized Identity Solutions in 2026 [Ranked & Scored]](http://cybersecuritynews.com/wp-content/uploads/2026/09/Best-Decentralized-Identity-Solutions-1.webp)







