2026年9月24日星期四

WordPress Remote Code Execution Vulnerability

WordPress Remote Code Execution Vulnerability

Release Date: 24 Sep 2026

A vulnerability was identified in identified in WordPress. A remote attacker could exploit this vulnerability to trigger remote code execution on the targeted system.

 

Note:

A proof-of-concept exploit have been published for CVE-2026-87902. If the active child or parent theme contains a top-level directory whose name starts with "page-", and a chosen local .php target file exists on the server and is readable by the web server account, then a remote attacker could exploit this vulnerability to trigger remote code execution. Hence, the risk level is rated as Medium Risk.


Impact

  • Remote Code Execution

System / Technologies affected

  • Wordpress 4.7.0 - 4.7.36
  • Wordpress 4.8.0 - 4.8.31
  • Wordpress 4.9.0 - 4.9.32
  • Wordpress 5.0.0 - 5.0.28
  • Wordpress 5.1.0 - 5.1.25
  • Wordpress 5.2.0 - 5.2.27
  • Wordpress 5.3.0 - 5.3.24
  • Wordpress 5.4.0 - 5.4.22
  • Wordpress 5.5.0 - 5.5.21
  • Wordpress 5.6.0 - 5.6.20
  • Wordpress 5.7.0 - 5.7.18
  • Wordpress 5.8.0 - 5.8.16
  • Wordpress 5.9.0 - 5.9.17
  • Wordpress 6.0.0 - 6.0.15
  • Wordpress 6.1.0 - 6.1.13
  • Wordpress 6.2.0 - 6.2.12
  • Wordpress 6.3.0 - 6.3.11
  • Wordpress 6.4.0 - 6.4.11
  • Wordpress 6.5.0 - 6.5.11
  • Wordpress 6.6.0 - 6.6.8
  • Wordpress 6.7.0 - 6.7.8
  • Wordpress 6.8.0 - 6.8.9
  • Wordpress 6.9.0 - 6.9.8
  • Wordpress 7.0.0 - 7.0.5
  • Wordpress 7.1.0 - 7.1.1

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:

 

https://wordpress.org/news/2026/09/wordpress-7-1-2-release/


Vulnerability Identifier


Source


Related Link

 


沒有留言:

發佈留言

WordPress 遠端執行程式碼漏洞

WordPress 遠端執行程式碼漏洞 發佈日期 : 2026 年 09 月 24 日 於 WordPress 發現一個漏洞。遠端攻擊者可利用這漏洞,於目標系統觸發遠端執行任意程式碼。   注意 : 針對 WordPress 新發現的漏洞 CVE-202...