WordPress Remote Code Execution Vulnerability
Release Date: 24 Sep 2026
A vulnerability was identified in identified in
WordPress. A remote attacker could exploit this vulnerability to
trigger remote code execution on the targeted system.
Note:
A proof-of-concept exploit have been published for
CVE-2026-87902. If the active child or parent theme contains a top-level
directory whose name starts with "page-", and a chosen local .php
target file exists on the server and is readable by the web server account,
then a remote attacker could exploit this vulnerability to trigger remote code
execution. Hence, the risk level is rated as Medium Risk.
Impact
- Remote
Code Execution
System / Technologies affected
- Wordpress
4.7.0 - 4.7.36
- Wordpress
4.8.0 - 4.8.31
- Wordpress
4.9.0 - 4.9.32
- Wordpress
5.0.0 - 5.0.28
- Wordpress
5.1.0 - 5.1.25
- Wordpress
5.2.0 - 5.2.27
- Wordpress
5.3.0 - 5.3.24
- Wordpress
5.4.0 - 5.4.22
- Wordpress
5.5.0 - 5.5.21
- Wordpress
5.6.0 - 5.6.20
- Wordpress
5.7.0 - 5.7.18
- Wordpress
5.8.0 - 5.8.16
- Wordpress
5.9.0 - 5.9.17
- Wordpress
6.0.0 - 6.0.15
- Wordpress
6.1.0 - 6.1.13
- Wordpress
6.2.0 - 6.2.12
- Wordpress
6.3.0 - 6.3.11
- Wordpress
6.4.0 - 6.4.11
- Wordpress
6.5.0 - 6.5.11
- Wordpress
6.6.0 - 6.6.8
- Wordpress
6.7.0 - 6.7.8
- Wordpress
6.8.0 - 6.8.9
- Wordpress
6.9.0 - 6.9.8
- Wordpress
7.0.0 - 7.0.5
- Wordpress
7.1.0 - 7.1.1
Solutions
Before installation of the software, please visit the
vendor web-site for more details.
Apply fixes issued by the vendor:
https://wordpress.org/news/2026/09/wordpress-7-1-2-release/
Vulnerability Identifier
Source
Related Link
- https://wordpress.org/news/2026/09/wordpress-7-1-2-release/
- https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp
沒有留言:
發佈留言