Imagine someone with no login, no password, no account on your site — able to run their own code on your server. That's the exact scenario WordPress just shut down.
On September 22, 2026, WordPress shipped version 7.1.2. It's a security release, and it addresses a critical severity vulnerability. When WordPress labels something "critical," it's not routine language. It means the stakes are high.
So What was Actually Broken?
Under specific conditions, an attacker didn't even need to be logged in. They could interfere with how WordPress resolves page templates, tricking the system into pulling in a readable local PHP file from outside the active theme's own directories.
If the server setup and active theme matched the right conditions, that could escalate into remote code execution. Translation: an outsider could potentially execute their own code on your site, without ever needing a username or password.
That's about as serious as a vulnerability gets.
Who Caught It
Security researcher Robert Ressl found the flaw and reported it responsibly, rather than exploiting it or going public first. That's exactly the kind of disclosure that keeps sites safe before attackers even know an opening exists.
For anyone tracking it officially, the issue is logged as CVE-2026-87902 / GHSA-7hp8-65ch-5whp.
What you need to do
*Update. Today, not sometime this week.
*
You've got a few easy paths:
Head to your WordPress Dashboard, click Updates, then Update Now
Grab WordPress 7.1.2 straight from WordPress.org
If automatic background updates are enabled on your site, it may already be handled
Managing more than one WordPress site? Don't just check your main one — go through all of them today.
What About Older Versions?
WordPress backported this fix to every branch still eligible for security support, reaching all the way back to version 4.7. That's a genuine courtesy, not something every project does.
Still, only the latest version of WordPress gets full, active support. If you've been relying on old-version backports as a long-term strategy, it's a good moment to plan a real upgrade.
Bottom Line
This isn't a feature refresh or a minor bug fix. It's a patch for a critical, unauthenticated vulnerability that could let attackers run code on sites that don't update.
If your site is still on an older version, this is the release you move on immediately — not later today, not tomorrow. Now.
Top comments (0)