An urgent security update is once again available for WordPress site operators. With the release of WordPress 7.1.2, developers are addressing a flaw rated as critical that could, under certain circumstances, allow attackers to execute their own malicious code on the server.
Insufficient File Name Sanitization: CVE-2026-87902
The security vulnerability is tracked under the identifier CVE-2026-87902 and has received a high CVSS rating of 9.2. It stems from insufficient validation of file names (category CWE-98). The bug was discovered and reported by Swiss security researcher Robert Ressi.
The issue arises during the execution of the WordPress function get_page_template(). This allows attackers not only to retrieve the standard page template, but also to include arbitrary .php files stored outside the intended directory on the web server. Since attackers can typically guess the paths and names of existing PHP files, this mechanism can be abused for unauthorized remote code execution (RCE).
Prerequisites for a Successful Attack
The flaw can be exploited if the name of the top-level directory containing the active template starts with the prefix page-. This applies to a wide range of templates. Affected designs include official CMS themes like Twenty Twelve and Twenty Fourteen, as well as widely used third-party templates.
Affected Versions and Recommendations
Administrators of WordPress installations should immediately verify which version is running on their systems. The update to version 7.1.2 is available immediately:
- Automatic updates: If automatic background updates are enabled on the installation, the fix will be applied without manual intervention.
- Manual updates: If auto-updates are disabled, the patch should be applied promptly via the administration dashboard.
- Older branches: The vulnerability also affects older versions of the CMS that are no longer officially supported. Developers are preparing security patches to be backported for versions starting from WordPress 4.7. Even older versions should not be in use anyway.
Sources: Heise – News















