π‘οΈ WordPress patched critical code execution flaw
WordPress released an urgent security update in version 7.1.2 on September 22, 2026, to fix a major vulnerability. This flaw, tracked as CVE-2026-87902, allows unauthenticated code execution under specific conditions on WordPress sites. The vulnerability stems from a path-traversal weakness in page-template resolution, scoring a critical CVSS 4.0 of 9.2. Exploitation depends on the website's theme layout and hosting environment being suitably configured. Administrators must update immediately, as older versions like 7.1.1 remain exposed. π‘οΈ