Welcome to HowToShipIt — practical how-to guides for developers: code, AI tools, and servers, explained step by step.

CVE-2026-87902: How to Check If Your WordPress Site Is Vulnerable and Patch It

Shield protecting a WordPress website from the CVE-2026-87902 path traversal vulnerability, security patch illustration

Why this one is different On September 22, 2026, WordPress released version 7.1.2 — a single-fix security release for CVE-2026-87902, an unauthenticated path-traversal flaw in page-template resolution. Within hours of the release, attackers were probing for it. This is now the default rhythm for critical WordPress core bugs: the patch itself tells attackers exactly where … Read more