WordPress security patch release for CVE-2026-87902
Security Patch Release
Summary
Hide ▲
Show ▼
WordPress released version 7.1.2 to fix CVE-2026-87902, a critical unauthenticated path traversal flaw that can lead to remote code execution under specific conditions. The patch was backported to branches down to 4.7, leaving releases before 4.6 without a fix. Administrators should treat the update as urgent because the flaw is already being actively exploited against vulnerable sites.
Related Happenings
WordPress core security release (7.1.1)
Security Patch Release
H score45
First: 18.09.2026 19:56
Last: 18.09.2026 19:56
Sources 1
About this happening:
WordPress 7.1.1 is a security release that fixed the Click2Shell WordPress Core flaw, a CSRF issue that could let a logged-in administrator open a crafted...
WordPress core security release (7.1.1)
Security Patch ReleaseAbout this happening: WordPress 7.1.1 is a security release that fixed the Click2Shell WordPress Core flaw, a CSRF issue that could let a logged-in administrator open a crafted...
WooCommerce Wholesale Lead Capture plugin 2.0.3.2 security update (CVE-2026-27540)
Security Patch Release
H score9
First: 15.09.2026 17:45
Last: 15.09.2026 17:45
Sources 1
About this happening:
The WooCommerce Wholesale Lead Capture plugin's version 2.0.3.2 release closed CVE-2026-27540, an unauthenticated arbitrary file-upload flaw that let attackers upl...
WooCommerce Wholesale Lead Capture plugin 2.0.3.2 security update (CVE-2026-27540)
Security Patch ReleaseAbout this happening: The WooCommerce Wholesale Lead Capture plugin's version 2.0.3.2 release closed CVE-2026-27540, an unauthenticated arbitrary file-upload flaw that let attackers upl...
ThemeFusion security patch release for CVE-2026-18431
Security Patch Release
H score43
First: 27.08.2026 00:33
Last: 27.08.2026 00:33
Sources 1
About this happening:
ThemeFusion released security fixes for Avada and Fusion Builder after disclosure of CVE-2026-18431, a critical 9.8 chain that can lead to arbitrary PHP code...
ThemeFusion security patch release for CVE-2026-18431
Security Patch ReleaseAbout this happening: ThemeFusion released security fixes for Avada and Fusion Builder after disclosure of CVE-2026-18431, a critical 9.8 chain that can lead to arbitrary PHP code...
Elementor Pro 4.2.2 security update for CVE-2026-32475
Security Patch Release
H score27
First: 20.08.2026 09:04
Last: 20.08.2026 09:04
Sources 1
About this happening:
Elementor Pro released version 4.2.2 on August 19, 2026 to fix CVE-2026-32475, a critical unauthenticated file-upload RCE in the plugin’s Forms module File U...
Elementor Pro 4.2.2 security update for CVE-2026-32475
Security Patch ReleaseAbout this happening: Elementor Pro released version 4.2.2 on August 19, 2026 to fix CVE-2026-32475, a critical unauthenticated file-upload RCE in the plugin’s Forms module File U...
Cozmoslabs security patch release for CVE-2026-15826
Security Patch Release
H score67
First: 17.08.2026 16:30
Last: 17.08.2026 16:30
Sources 1
About this happening:
Cozmoslabs released User Profile Builder 3.16.5 to fix CVE-2026-15826, an authentication bypass affecting more than 40,000 WordPress sites. The patch closes a flaw...
Cozmoslabs security patch release for CVE-2026-15826
Security Patch ReleaseAbout this happening: Cozmoslabs released User Profile Builder 3.16.5 to fix CVE-2026-15826, an authentication bypass affecting more than 40,000 WordPress sites. The patch closes a flaw...
Timeline
-
23.09.2026 21:31 1 articles · 2h ago
WordPress security patch release for CVE-2026-87902
Initial DisclosureWordPress released 7.1.2 to fix CVE-2026-87902, an unauthenticated path traversal flaw with potential RCE impact. The fix was backported to branches down to 4.7, while releases before 4.6 were left without a patch.
Show sources
- Hackers start exploiting critical WordPress flaw for code execution — www.bleepingcomputer.com — 23.09.2026 21:31
-
23.09.2026 21:31 1 articles · 2h ago
Patchstack observes WordPress exploitation of CVE-2026-87902
Exploitation ObservedPatchstack observed malicious traffic against WordPress sites vulnerable to CVE-2026-87902 at 17:44 UTC on September 22, after attackers moved beyond reconnaissance and began writing files to disk that can execute shell commands when accessed.
Show sources
- Hackers start exploiting critical WordPress flaw for code execution — www.bleepingcomputer.com — 23.09.2026 21:31