Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Snorkel AI triples valuation to $3.5B as demand for AI training data booms

    September 23, 2026

    Rogue external MFA providers can steal passwords during logins

    September 23, 2026

    Rogue iPhone app escapes iOS sandbox to hijack $580,000 in USDT

    September 23, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Snorkel AI triples valuation to $3.5B as demand for AI training data booms
    • Rogue external MFA providers can steal passwords during logins
    • Rogue iPhone app escapes iOS sandbox to hijack $580,000 in USDT
    • MIT’s tiny flying robot gets 450% faster with AI
    • California Tribes receive beach and ancestral village site back from transportation authority
    • A proposed data center is changing the conversation in this Indiana farming community
    • Minority ethnic NHS staff pay a heavy price for speaking up about patient safety | NHS
    • US judge blocks deportation of DoorDash driver shot by ICE
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 23
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 22, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalSep 22, 2026Vulnerability / Web Security

    WordPress has fixed a critical flaw in its core software that lets an attacker with no account make a site load a PHP file from outside its theme folders.

    On some servers, that can go further, allowing the attacker to run their own code. The fix shipped on September 22 in WordPress 7.1.2, with fixes for every branch the project still supports, back to 4.7, and WordPress is telling site owners to update now.

    WordPress rates the flaw as critical, assigns it a CVSS score of 9.2, and assigns it CVE-2026-87902. Reaching it requires no account and no action from a logged-in user.

    Cybersecurity

    Every version from 4.7.0 through 7.1.1 is affected. That includes 7.1.1, from WordPress’s September 17 security release, so a site updated less than a week ago still needs this one. It is a separate flaw from the ones that the release fixed.

    The release to update to depends on the branch you run:

    Branch you run Update to
    7.1.x 7.1.2
    7.0.x 7.0.6
    6.9.x 6.9.9
    6.8.x 6.8.10
    6.7.x 6.7.9
    6.6.x 6.6.9

    WordPress backported the fix to every older branch it still supports as a courtesy, down to 4.7.37. The full list is in the release notes.

    Sites with automatic background updates enabled will start the update automatically. Others can update from the dashboard under Updates, or download the release from WordPress.org. WordPress does not offer a separate workaround, so updating is the fix.

    Loading a local PHP file runs whatever that file already does. Turning that into code of the attacker’s choosing requires a second condition: the server must already have a PHP file that does something useful when loaded. That is the “some servers” in WordPress’s description, and it is why the flaw does not mean full code execution on every affected site.

    Cybersecurity

    The flaw is in how WordPress chooses the template file for a page. One of the file names it builds comes from part of the web address, and on affected versions WordPress did not run that value through its own check for ../ traversal steps, the check the neighboring code already used.

    Because the name is built as page-{value}.php, a working attack also needs the active theme to have a top-level folder whose name starts with page-, and the target file has to end in .php. Some themes, including older default WordPress themes, ship a folder that fits.

    Security vendor Patchstack, in its own analysis, says two checks tell a site owner how exposed they are: whether the active theme has a top-level folder whose name begins with page-, and whether PHP is running with a setting called register_argc_argv turned on, which a known code-execution technique depends on.

    Neither is a fix, the company says, but both show how close a site is to the worst case. That setting is off by default on PHP 8.5 and on by default on older PHP versions.

    As of September 22, there were no reports of the flaw being used in attacks, no public proof-of-concept exploit, and no entry for it in the U.S. CISA Known Exploited Vulnerabilities catalog.

    WordPress credited Robert Ressl with finding and reporting the flaw. The Hacker News has contacted WordPress and Ressl for comment.

    Code critical enable Execution Flaw issues patch Servers WordPress
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Rogue external MFA providers can steal passwords during logins

    Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks

    Chinese hackers exploit WordPress, Zyxel flaws to steal govt data

    Nightmare Eclipse Drops New Microsoft Defender Exploit After Revealing Identity

    BigCommerce Data Stolen via Ribon Apps Hack

    New ClosedQuorum Windows malware uses AI for attack decisions

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Snorkel AI triples valuation to $3.5B as demand for AI training data booms

    September 23, 2026

    Rogue external MFA providers can steal passwords during logins

    September 23, 2026

    Rogue iPhone app escapes iOS sandbox to hijack $580,000 in USDT

    September 23, 2026

    MIT’s tiny flying robot gets 450% faster with AI

    September 23, 2026
    Latest Posts

    COLDCARD security audit phishing attack installs remote access tool

    August 5, 2026

    Reddit aims to make ‘karma’ less important for first-time posters with shift to AI moderation tools

    August 5, 2026

    Right turn on green: is the Telegraph changing its tune on the climate? | Daily Telegraph

    August 5, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Snorkel AI triples valuation to $3.5B as demand for AI training data booms

    September 23, 2026

    Rogue external MFA providers can steal passwords during logins

    September 23, 2026

    Rogue iPhone app escapes iOS sandbox to hijack $580,000 in USDT

    September 23, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.