Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Urgent WordPress Update Fixes Major Security Vulnerability

Urgent WordPress Update Fixes Major Security Vulnerability

Posted on September 22, 2026 By CWS

WordPress has addressed a significant security issue in its core platform, affecting all versions from 4.7.0 to 7.1.1. This critical vulnerability enables attackers to execute PHP files from outside the theme directories, potentially allowing them to run malicious code on certain servers.

The security patch was released on September 22, 2026, through version 7.1.2, and WordPress encourages all users to update immediately. The flaw has been rated critical with a CVSS score of 9.2 and is identified as CVE-2026-87902. Notably, the vulnerability does not require an account or any action from authenticated users to be exploited.

Impact and Versions Affected

The vulnerability impacts every version from 4.7.0 up to the recent 7.1.1 release. Even sites updated less than a week prior with the September 17 security patch are vulnerable. The issue is distinct from flaws addressed in previous updates, necessitating an immediate upgrade.

The recommended updates vary based on the version branch being used: version 7.1.x should move to 7.1.2, 7.0.x to 7.0.6, 6.9.x to 6.9.9, and so forth. WordPress has also backported the fix to older branches still under support, such as 4.7.37.

Implementation and Technical Details

Sites with automatic background updates will receive the patch automatically. Others should manually update through the dashboard or download the release from WordPress.org. There is no alternative workaround, making the update essential.

The flaw arises from how WordPress selects template files for pages. It involves constructing file names from web addresses, which, in vulnerable versions, were not adequately checked for directory traversal attempts. For a successful attack, the active theme must have a top-level folder beginning with page- and end with .php.

Security Recommendations and Vendor Analysis

Security firm Patchstack advises site owners to check if their active theme includes a top-level folder named with page- and whether the PHP setting register_argc_argv is enabled, as these factors increase vulnerability risks. However, neither serves as a definitive solution.

As of the patch release date, no exploits have been reported, and no proof-of-concept attacks are publicly available. The U.S. CISA Known Exploited Vulnerabilities catalog does not yet list this flaw.

Credit for discovering and reporting the vulnerability goes to Robert Ressl. The Hacker News has reached out to both WordPress and Ressl for further comments on the issue.

The Hacker News Tags:automatic updates, code execution, critical flaw, CVE-2026-87902, Cybersecurity, Patchstack, PHP, Security, theme folders, Update, Vulnerability, web security, WordPress

Post navigation

Previous Post: Aembit Integrates Okta’s Cross App Access for AI Control
Next Post: Enhancing SOC Efficiency with Threat Intelligence

Related Posts

OpenAI Introduces ChatGPT Lockdown Mode for Enhanced Security OpenAI Introduces ChatGPT Lockdown Mode for Enhanced Security The Hacker News
Fake LastPass Installer Uses Signed Driver to Bypass Security Fake LastPass Installer Uses Signed Driver to Bypass Security The Hacker News
CanisterWorm Exploits Trivy Attack, Targets npm Packages CanisterWorm Exploits Trivy Attack, Targets npm Packages The Hacker News
Enhancing Defense with Automated Exposure Validation Enhancing Defense with Automated Exposure Validation The Hacker News
Discover the AI Tools Fueling the Next Cybercrime Wave — Watch the Webinar Discover the AI Tools Fueling the Next Cybercrime Wave — Watch the Webinar The Hacker News
New EDDIESTEALER Malware Bypasses Chrome’s App-Bound Encryption to Steal Browser Data New EDDIESTEALER Malware Bypasses Chrome’s App-Bound Encryption to Steal Browser Data The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Enhancing SOC Efficiency with Threat Intelligence
  • Urgent WordPress Update Fixes Major Security Vulnerability
  • Aembit Integrates Okta’s Cross App Access for AI Control
  • Check Point Addresses Management Server Zero-Day Exploit
  • Critical Flaw in Check Point Servers Actively Exploited

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Enhancing SOC Efficiency with Threat Intelligence
  • Urgent WordPress Update Fixes Major Security Vulnerability
  • Aembit Integrates Okta’s Cross App Access for AI Control
  • Check Point Addresses Management Server Zero-Day Exploit
  • Critical Flaw in Check Point Servers Actively Exploited

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark