WordPress releases security update
WordPress versions prior to 7.1.2 are affected by a security vulnerability. An attacker could exploit this vulnerability to trigger remote code execution. Security vulnerability was fixed in WordPress 7.1.2.
WordPress reports that security vulnerability (CVE-2026-87902) is likely to be exploited in the wild.
More information on vulnerabilities and update is available in WordPress 7.1.2 release note – wordpress.org.
25 September 2026