
Attackers Exploit WordPress Path Traversal Flaw Within Hours of Patch Release
WordPress released version 7.1.2 on September 22 to fix CVE-2026-87902, a critical unauthenticated path traversal vulnerability. The flaw allows attackers to load arbitrary PHP files, potentially leading to remote code execution on servers with specific configurations. Attackers began exploiting the vulnerability within hours of the patch, escalating from reconnaissance to writing malicious files. Site owners are urged to update immediately, as the fix is backported to all supported branches down to version 4.7.
