
WordPress has shipped an urgent security update after the discovery of CVE-2026-87902, a critical unauthenticated path traversal flaw in WordPress Core that can, under the right conditions, lead to remote code execution. The WordPress Security Team released WordPress 7.1.2 on…


















