cybersecuritynews.comยท23 september 2026
Critical WordPress Core Vulnerability Lets Attackers Execute Code Without Logging In

security
WordPress update
CVE-2026-87902
Cyber Security News
server configuration
database credentials
WordPress core
WordPress theme
remote code execution
template resolution
security vulnerability
WordPress
Robert Ressl
PHP
web shells
WordPress security team
cybersecuritynews.com
WordPress released version 7.1.2 to fix a critical vulnerability (CVE-2026-87902) that allows unauthenticated attackers to execute code under specific conditions. The flaw affects WordPress page template resolution, potentially enabling remote code execution. Security researcher Robert Ressl disclosed the issue to the WordPress security team. Administrators should update immediately, as exploitation does not require authentication and can lead to severe consequences like data theft or malware distribution.