Patch released WordPress rce web-app
WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers
CVE Tools coverage
WordPress has released fixes for CVE-2026-87902, a CVSS 9.2 core vulnerability affecting versions 4.7.0 through 7.1.1. An unauthenticated attacker could cause WordPress to load PHP files outside theme directories, which could lead to attacker-controlled code execution on certain server and theme configurations. Site owners should update to WordPress 7.1.2 or the applicable supported-branch release; no workaround is available.