
WordPress 7.1.2 Patched as Attackers Exploit Critical Path Traversal Flaw
WordPress released version 7.1.2 on September 22 to fix CVE-2026-87902, a critical unauthenticated path traversal vulnerability. Attackers began exploiting the flaw within hours of the patch, escalating from reconnaissance to writing malicious files that execute shell commands. The vulnerability, rated 9.2/10, affects versions 4.7 through 7.1.1 and requires specific server configurations for full remote code execution.













