Security News · WordPress

WordPress CVE-2026-87902
Exploited. Fixed in 7.1.2.

A flaw in how WordPress picks a page template can let an attacker with no login run code on the server, when two conditions are met. WordPress fixed it on September 22, 2026, and CISA listed it as exploited on September 25. If a site of yours runs WordPress, confirm it updated.