WordPress 7.1.2 fixes critical unauthenticated path traversal vulnerability (CVE-2026-87902)
WordPress 7.1.2 fixes critical unauthenticated path traversal vulnerability (CVE-2026-87902) 2026-09-23 at 12:01 By Sinisa Markovic WordPress released version 7.1.2 to fix a critical flaw that lets an unauthenticated attacker make the software load a PHP file of the attacker’s choosing from outside the site’s active theme folders. On sites where the server and the active […]