WordPress 7.1.2 fixes a critical template-resolution flaw exploited for code execution
On September 22, 2026, WordPress shipped version 7.1.2 to fix CVE-2026-87902, a critical flaw that lets an unauthenticated attacker include a chosen local PHP file during page-template resolution and, under certain conditions, execute code. Update immediately, especially sites without automatic updates.