This security release features a fix for a critical severity security vulnerability.
Because this is a security release, it is recommended that you update your sites immediately.
You can download WordPress 7.1.2 from WordPress.org, or visit your WordPress Dashboard, click “Updates”, and then click “Update Now”. If you have sites that support automatic background updates, the update process will begin automatically.
The security team would like to thank Robert Ressl for responsibly disclosing that an unauthenticated attacker can, under certain conditions, make page template resolution include a chosen readable local PHP file outside the active theme directories. If relevant pre-conditions for both the server environment and the active theme are met, this can lead to remote code execution (RCE).
This release was led by John Blackbourn. WordPress 7.1.2 would not have been possible without the contributions of the following people:
Aaron Jorbin, Aki Hamano, Alex Concha, Ehtisham Siddiqui, fiocavallari, Jb Audras, Jeffrey Paul, Jeremy Felt, Joe McGill, John Blackbourn, Lance Willett, Manuel Camargo, marcs0h, martin.krcho, Mukesh Panchal, Olga Gleckler, Pascal Birchler, Peter Wilson, Rajin Sharwar, Ressl, Shail Mehta, Stephanie Walters, and vortfu.
Further details can be found in the advisory: CVE-2026-87902 / GHSA-7hp8-65ch-5whp.
As a courtesy, the security fix is being backported to all branches eligible to receive security fixes (currently through 4.7). As a reminder, only the most recent version of WordPress is actively supported. The backports are in progress and will ship as they become ready.
Dinesh Thakkar, the visionary founder of Angel One, has made headlines by acquiring a full…
Bedi, who was part of the Chennai Super Kings (CSK) set-up during IPL 2025 and…
Post Content
Foreign ministers from four nations affirmed Saudi Arabia's right to self-defense. They stressed the importance…
Sardar Shaukat Ali Kashmiri has appealed to the UN Human Rights Council for urgent intervention…