cybersecuritynews.comยท23 september 2026

Critical WordPress Core Vulnerability Lets Attackers Execute Code Without Logging In

Image for the article: Critical WordPress Core Vulnerability Lets Attackers Execute Code Without Logging In
Image via cybersecuritynews.com

WordPress released version 7.1.2 to fix a critical vulnerability (CVE-2026-87902) that allows unauthenticated attackers to execute code under specific conditions. The flaw affects WordPress page template resolution, potentially enabling remote code execution. Security researcher Robert Ressl disclosed the issue to the WordPress security team. Administrators should update immediately, as exploitation does not require authentication and can lead to severe consequences like data theft or malware distribution.