Back to Security Advisories

WordPress 7.1.2 Release

WordPress 7.1.2 is a security release fixing a critical severity vulnerability (CVE-2026-87902, CVSS 8.1): under certain conditions an unauthenticated attacker could make page template resolution include a chosen readable local PHP file outside the active template. Because the flaw is exploitable by unauthenticated attackers, WordPress recommends updating all sites immediately — the update rolls out automatically on sites with background updates enabled.

Critical 8.1 CVSS Actively exploited
WordPress

Affected Versions

7.1.2

What this means under a SharedLicense license

An unauthenticated attacker can steer page template resolution into loading an arbitrary readable local PHP file, which can disclose sensitive code or data depending on what the included file executes or reveals.


This security release features a fix for a critical severity security vulnerability.

Because this is a security release, it is recommended that you update your sites immediately.

You can download WordPress 7.1.2 from WordPress.org, or visit your WordPress Dashboard, click “Updates”, and then click “Update Now”. If you have sites that support automatic background updates, the update process will begin automatically.

Security update included in this release

The security team would like to thank Robert Ressl for responsibly disclosing that an unauthenticated attacker can, under certain conditions, make page template resolution include a chosen readable local PHP file outside the active theme directories. If relevant pre-conditions for both the server environment and the active theme are met, this can lead to remote code execution (RCE).

Thank you to these WordPress contributors

This release was led by John Blackbourn. WordPress 7.1.2 would not have been possible without the contributions of the following people:

Aaron Jorbin, Aki Hamano, Alex Concha, Ehtisham Siddiqui, fiocavallari, Jb Audras, Jeffrey Paul, Jeremy Felt, Joe McGill, John Blackbourn, Jon Surrell, Lance Willett, Manuel Camargo, marcs0h, martin.krcho, Mukesh Panchal, Olga Gleckler, Pascal Birchler, Peter Wilson, Rajin Sharwar, Ressl, Rudy Faile, Sergey Biryukov, Shail Mehta, Stephanie Walters, and vortfu.

CVE and GHSA references

Further details can be found in the advisory: CVE-2026-87902 / GHSA-7hp8-65ch-5whp.

Backports

As a courtesy, the security fix was backported to all branches eligible to receive security fixes (currently through 4.7). As a reminder, only the most recent version of WordPress is actively supported.

Share this:

Frequently Asked Questions

What is CVE-2026-87902?
It is the CVE ID for the critical vulnerability fixed in WordPress 7.1.2: page template resolution could, under certain conditions, be made by an unauthenticated attacker to include a chosen readable local PHP file outside the active template. NVD rates it 8.1 (High band); WordPress labels the issue critical severity.
Which WordPress versions are affected?
WordPress versions before 7.1.2. The fix ships in 7.1.2, and sites running the 7.0 branch should be on 7.0.3 or later, which contains the equivalent fixes for that branch.
How do I update to WordPress 7.1.2?
Download it from WordPress.org or go to Dashboard → Updates → Update Now. Sites with automatic background updates will receive it without action. Hosting customers on managed platforms can also ask their host to confirm the running version.
Is CVE-2026-87902 being exploited in the wild?
WordPress's release post credits Robert Ressl with a responsible disclosure and does not report any active exploitation. Because the flaw requires no authentication, apply the update immediately rather than waiting.

Check your system for vulnerabilities

Select your product and operating system to see the exact fix commands that apply to you.

Check Your System