Security0 views

WordPress Patches Critical Remote Code Execution Vulnerability

WordPress has released a critical security fix addressing CVE-2026-87902, a vulnerability that allows unauthenticated attackers to execute arbitrary PHP code on affected servers. The flaw enables an attacker to force a website to load a PHP file from outside the designated theme directories, creating a direct path to remote code execution.

The patch has been made available for all affected versions, spanning from WordPress 4.7 through 7.1. Security experts strongly recommend updating immediately. Given the severity of remote code execution vulnerabilities and the public disclosure of this issue, delays in patching leave sites exposed to active exploitation.