Patch released WordPress web-app rce
WordPress 7.1.2 fixes critical unauthenticated path traversal vulnerability (CVE-2026-87902)
CVE Tools coverage
WordPress has released 7.1.2 to address CVE-2026-87902, an unauthenticated path traversal vulnerability affecting versions 4.7.0 through 7.1.1. The flaw in get_page_template() can let remote attackers cause WordPress to include readable PHP files outside the active theme directories, potentially leading to server-side code execution under certain configurations. WordPress also backported the fix to supported older branches, and site operators should update promptly.