we_are_coded.by CODE · The world, decoded
БГ
WordPress

WordPress 7.1.2 closes a critical hole that can let outside code in without an account

WordPress.org · event date: 22 September 2026Security

The urgent release of 22 September fixes CVE-2026-87902: an attacker with no password can make WordPress load a chosen PHP file from the server. With certain themes and server settings this can lead to remote code execution. The fix has been backported all the way to version 4.7.

In short
  • CVE-2026-87902 scores 9.2 on CVSS v4 in the WordPress advisory and requires neither an account nor any user action.
  • It is dangerous if the active theme has a folder whose name starts with page-, as in Twenty Twelve, Twenty Fourteen, Neve, Hestia and Sydney.
  • The second key is a PHP file on the server that can be abused, such as pearcmd.php with register_argc_argv switched on.
Checked on1 October 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

Two conditions have to meet for trouble. One is in your theme, the other in your server. That is why it is worth checking both, not just the version.

The hole is in the way WordPress decides which page template to load. An attacker with no account can trick it into including a PHP file outside the theme folder. That alone is bad. If both the theme and the server meet the conditions, it can lead to execution of outside code.

The facts: on 22 September 2026 WordPress released version 7.1.2 as an urgent security release because of CVE-2026-87902 (GHSA-7hp8-65ch-5whp), rated critical at 9.2 on CVSS v4 in the WordPress advisory. An unauthenticated attacker can make the get_page_template() function include a chosen readable local .php file outside the active theme directories, which under certain conditions leads to remote code execution. There are two conditions: the active theme or its parent must have a top-level folder whose name starts with page- (the legacy Twenty Twelve and Twenty Fourteen are affected, as are the popular Neve, Hestia and Sydney), and the server must hold a readable .php file that can be used - for example pearcmd.php with the register_argc_argv setting on. According to the advisory, the official PHP image for Docker and the default cPanel configuration with PHP before 8.5 are affected. The fix has been backported to all branches down to 4.7, including 7.0.6, 6.9.9 and 6.8.10. The hole was discovered and reported by Robert Ressl.

What to check today

First the version. If automatic updates work, the site is probably already on the patched one. If they do not, you update by hand.

Then the theme. Open its folder and see whether there is a subfolder whose name starts with page-. If you use one of the five themes listed, or a child theme of one, assume you have it.

Finally the server. If you are on cPanel with the default configuration and PHP before 8.5, or run WordPress on the official PHP image for Docker, the server condition is met for you.

The hole needs two conditions. The patch needs one action.

You update to 7.1.2 or to the patched release of your branch. Today, before someone else has read the same advisory.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→WordPress.org - WordPress 7.1.2 Release, 22.09.2026→GitHub Security Advisory GHSA-7hp8-65ch-5whp (WordPress)→CVE-2026-87902 (NVD)
Original: https://wearecoded.com/en/articles/wordpress-712-kritichna-dupka-v-shablonite.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news