> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> WordPress 7.1.2 fixes critical unauthenticated path traversal vulnerability (CVE-2026-87902)

[SOURCE] Help Net Security [AUTHOR: Sinisa Markovic] [DATE: 23/09/2026 09:01] [LANGUAGE: EN]
WordPress released version 7.1.2 to fix a critical flaw that lets an unauthenticated attacker make the software load a PHP file of the attacker’s choosing from outside the site’s active theme folders. On sites where the server and the active theme meet certain conditions, the attacker can go on to run code on the server. The project tracks the flaw as CVE-2026-87902 and lists every release from 4.7.0 through 7.1.1 as affected. The attacker needs … More → The post WordPress 7.1.2 fixes critical unauthenticated path traversal vulnerability (CVE-2026-87902) appeared first on Help Net Security.
[messages.read_original_source] →