CVE-2026-87902: How to Check If Your WordPress Site Is Vulnerable and Patch It
Why this one is different On September 22, 2026, WordPress released version 7.1.2 — a single-fix security release for CVE-2026-87902, an unauthenticated path-traversal flaw in page-template resolution. Within hours of the release, attackers were probing for it. This is now the default rhythm for critical WordPress core bugs: the patch itself tells attackers exactly where … Read more