CVE Tools
Back to feed
Patch released WordPress web-app rce

WordPress 7.1.2 fixes critical unauthenticated path traversal vulnerability (CVE-2026-87902)

Help Net Security·By Sinisa Markovic··1 min read
CVE Tools coverage

WordPress has released 7.1.2 to address CVE-2026-87902, an unauthenticated path traversal vulnerability affecting versions 4.7.0 through 7.1.1. The flaw in get_page_template() can let remote attackers cause WordPress to include readable PHP files outside the active theme directories, potentially leading to server-side code execution under certain configurations. WordPress also backported the fix to supported older branches, and site operators should update promptly.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store