← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 24, 2026 · 20:26via CSO Online

WordPress patches a critical severity security vulnerability

Brief

WordPress has patched what it described as a critical severity security vulnerability that would allow an unauthenticated attacker full remote code execution (RCE) capabilities. There have already been reports of attacks in the wild.

Given its popularity, WordPress has frequently been under attack , and patched another maximum severity bug allowing RCE in July. WordPress said the current hole, tracked as CVE-2026-87902 , was discovered and reported to the company by Switzerland-based security researcher Robert Ressl .

The post announcing the WordPress 7.

  • 2 security release said that the fix addressed an issue where “an unauthenticated attacker can, under certain conditions, make page template resolution include a chosen readable local PHP file outside the active theme directories.
Read more on CSO Online→