WordPress: Critical WordPress Core Vulnerability Lets Attackers Execute Code Without Logging In

WordPress: Critical WordPress Core Vulnerability Lets Attackers Execute Code Without Logging In

WordPress Patches Critical RCE Vulnerability in Latest Update

WordPress has released version 7.1.2 to address a critical security flaw (CVE-2026-87902) that could enable unauthenticated remote code execution (RCE) on vulnerable websites under specific conditions. The vulnerability, disclosed by security researcher Robert Ressl, affects WordPress’s page template resolution mechanism, allowing attackers to manipulate template selection and execute arbitrary PHP files outside the intended theme directory.

Exploitation does not require authentication, making unpatched sites prime targets for automated scanning and opportunistic attacks. If successfully exploited, the flaw could allow threat actors to deploy web shells, steal database credentials, modify site content, create admin accounts, redirect visitors, or distribute malware. The severity of the issue stems from its potential to fully compromise both the website and underlying server.

The vulnerability’s impact depends on server configuration, active theme, and the presence of readable PHP files outside theme directories. While not all WordPress installations are exploitable, the lack of authentication requirements heightens the risk for exposed sites.

WordPress has backported the fix to supported legacy branches (down to version 4.7), though only the latest release (7.1.2) receives active support. Administrators are advised to update immediately via the WordPress Dashboard or manual download. Sites with automatic background updates may receive the patch automatically.

Post-update, security teams should verify patch installation, review logs for suspicious template-related requests or unauthorized PHP execution, and audit themes or custom code affecting template selection. The flaw underscores the urgency of patching, given its potential for full site and server compromise.

Source: https://cybersecuritynews.com/wordpress-core-vulnerability/

WordPress TPRM report: https://www.rankiteo.com/company/wordpress

"id": "wor1790152041",
"linkid": "wordpress",
"type": "Vulnerability",
"date": "9/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': 'Websites using WordPress '
                                              'versions prior to 7.1.2 and '
                                              'legacy branches down to 4.7',
                        'industry': 'Technology/Software',
                        'name': 'WordPress',
                        'type': 'Content Management System (CMS)'}],
 'attack_vector': 'Unauthenticated exploitation via page template resolution '
                  'mechanism',
 'customer_advisories': 'WordPress administrators advised to update '
                        'immediately via the WordPress Dashboard or manual '
                        'download.',
 'data_breach': {'file_types_exposed': ['PHP files'],
                 'sensitivity_of_data': 'High (personally identifiable '
                                        'information, administrative access)',
                 'type_of_data_compromised': ['Database credentials',
                                              'Site content',
                                              'Admin accounts',
                                              'Visitor data']},
 'description': 'WordPress has released version 7.1.2 to address a critical '
                'security flaw (CVE-2026-87902) that could enable '
                'unauthenticated remote code execution (RCE) on vulnerable '
                'websites under specific conditions. The vulnerability affects '
                'WordPress’s page template resolution mechanism, allowing '
                'attackers to manipulate template selection and execute '
                'arbitrary PHP files outside the intended theme directory. '
                'Exploitation does not require authentication, making '
                'unpatched sites prime targets for automated scanning and '
                'opportunistic attacks. If successfully exploited, the flaw '
                'could allow threat actors to deploy web shells, steal '
                'database credentials, modify site content, create admin '
                'accounts, redirect visitors, or distribute malware.',
 'impact': {'data_compromised': 'Database credentials, site content, admin '
                                'accounts, visitor data',
            'operational_impact': 'Full site and server compromise, '
                                  'unauthorized PHP execution, malware '
                                  'distribution',
            'systems_affected': 'WordPress websites (versions prior to 7.1.2 '
                                'and legacy branches down to 4.7)'},
 'lessons_learned': 'Urgency of patching critical vulnerabilities, especially '
                    'those enabling unauthenticated RCE; importance of '
                    'auditing themes and custom code affecting template '
                    'selection; need for proactive log monitoring for '
                    'suspicious activity.',
 'post_incident_analysis': {'corrective_actions': 'Patch released (version '
                                                  '7.1.2); backported fixes '
                                                  'for legacy branches; '
                                                  'recommendations for log '
                                                  'review and theme/code '
                                                  'audits.',
                            'root_causes': 'Vulnerability in WordPress’s page '
                                           'template resolution mechanism '
                                           'allowing unauthenticated '
                                           'manipulation of template selection '
                                           'and execution of arbitrary PHP '
                                           'files.'},
 'recommendations': 'Immediately update to WordPress 7.1.2 or apply backported '
                    'patches; verify patch installation; review logs for signs '
                    'of exploitation; audit themes and custom code; enable '
                    'automatic updates where possible; monitor for '
                    'unauthorized PHP execution.',
 'references': [{'source': 'Security researcher Robert Ressl'}],
 'response': {'communication_strategy': 'Public disclosure via security '
                                        'advisory',
              'containment_measures': 'Patch released (version 7.1.2 and '
                                      'backported to legacy branches)',
              'enhanced_monitoring': 'Review logs for suspicious activity',
              'remediation_measures': 'Update to WordPress 7.1.2 or apply '
                                      'backported patches; verify patch '
                                      'installation; review logs for '
                                      'suspicious template-related requests or '
                                      'unauthorized PHP execution; audit '
                                      'themes or custom code affecting '
                                      'template selection'},
 'title': 'WordPress Patches Critical RCE Vulnerability in Latest Update',
 'type': 'Remote Code Execution (RCE)',
 'vulnerability_exploited': 'CVE-2026-87902'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.