Find notable cyber news and cases, enriched with sources, timelines, and signals.

WordPress security patch release for CVE-2026-87902

Security Patch Release
First reported
Last updated
Happening score
H score 47
1 unique sources, 1 articles

Summary

Hide ▲

WordPress released version 7.1.2 to fix CVE-2026-87902, a critical unauthenticated path traversal flaw that can lead to remote code execution under specific conditions. The patch was backported to branches down to 4.7, leaving releases before 4.6 without a fix. Administrators should treat the update as urgent because the flaw is already being actively exploited against vulnerable sites.

Related Happenings

WordPress core security release (7.1.1)

Security Patch Release
H score45 First: 18.09.2026 19:56 Last: 18.09.2026 19:56 Sources 1

About this happening: WordPress 7.1.1 is a security release that fixed the Click2Shell WordPress Core flaw, a CSRF issue that could let a logged-in administrator open a crafted...

WooCommerce Wholesale Lead Capture plugin 2.0.3.2 security update (CVE-2026-27540)

Security Patch Release
H score9 First: 15.09.2026 17:45 Last: 15.09.2026 17:45 Sources 1

About this happening: The WooCommerce Wholesale Lead Capture plugin's version 2.0.3.2 release closed CVE-2026-27540, an unauthenticated arbitrary file-upload flaw that let attackers upl...

ThemeFusion security patch release for CVE-2026-18431

Security Patch Release
H score43 First: 27.08.2026 00:33 Last: 27.08.2026 00:33 Sources 1

About this happening: ThemeFusion released security fixes for Avada and Fusion Builder after disclosure of CVE-2026-18431, a critical 9.8 chain that can lead to arbitrary PHP code...

Elementor Pro 4.2.2 security update for CVE-2026-32475

Security Patch Release
H score27 First: 20.08.2026 09:04 Last: 20.08.2026 09:04 Sources 1

About this happening: Elementor Pro released version 4.2.2 on August 19, 2026 to fix CVE-2026-32475, a critical unauthenticated file-upload RCE in the plugin’s Forms module File U...

Cozmoslabs security patch release for CVE-2026-15826

Security Patch Release
H score67 First: 17.08.2026 16:30 Last: 17.08.2026 16:30 Sources 1

About this happening: Cozmoslabs released User Profile Builder 3.16.5 to fix CVE-2026-15826, an authentication bypass affecting more than 40,000 WordPress sites. The patch closes a flaw...

Timeline

  1. 23.09.2026 21:31 1 articles · 2h ago

    WordPress security patch release for CVE-2026-87902

    Initial Disclosure

    WordPress released 7.1.2 to fix CVE-2026-87902, an unauthenticated path traversal flaw with potential RCE impact. The fix was backported to branches down to 4.7, while releases before 4.6 were left without a patch.

    Show sources
  2. 23.09.2026 21:31 1 articles · 2h ago

    Patchstack observes WordPress exploitation of CVE-2026-87902

    Exploitation Observed

    Patchstack observed malicious traffic against WordPress sites vulnerable to CVE-2026-87902 at 17:44 UTC on September 22, after attackers moved beyond reconnaissance and began writing files to disk that can execute shell commands when accessed.

    Show sources