WordPress 7.1.2 patches critical unauthenticated path‑traversal bug
WordPress has released version 7.1.2 to close a critical unauthenticated path‑traversal vulnerability tracked as CVE‑2026‑87902. The flaw allowed an attacker without any credentials to force the platform to load a PHP file located outside the active theme directory, potentially leading to remote code execution on vulnerable sites.
All WordPress installations from version 4.7.0 through 7.1.1 are listed as affected. The exploit works only when the web server’s configuration and the active theme meet specific conditions that permit the attacker to supply a path to a malicious PHP file. Once the file is loaded, the attacker can execute arbitrary code, which could compromise the entire site and the underlying server.
The vulnerability is unauthenticated, meaning no login or user privilege is required to trigger it. Attackers typically craft a specially crafted URL that includes the malicious path, then send it to site owners or embed it in phishing emails. If a site administrator visits the URL, the server may process the request and load the attacker‑controlled script.
WordPress users should update to 7.1.2 immediately. The update replaces the vulnerable file handling routine with stricter validation that blocks paths pointing outside the theme folder. Site owners should also review their server configuration to ensure that PHP files cannot be executed from unauthorized directories. Disabling file editing from the dashboard and limiting file permissions are additional safeguards.
At ComputerScams.com we recommend using the free “Site Health” scanner to check for outdated plugins and themes, and the “File Integrity Monitor” tool to detect unexpected changes to core files. Regular backups and a robust firewall further reduce the risk of exploitation.
While the patch addresses the known issue, the broader lesson remains: keep WordPress core, plugins, and themes up to date, and restrict file permissions wherever possible. Attackers often look for the oldest unpatched sites to launch mass exploitation campaigns.
A simple step you can take right now is to log into your WordPress admin panel, navigate to Updates, and apply the 7.1.2 release. Keeping software current is the most effective defense against many online scams and attacks.
Source: Read the original report