Home / Sep 23, 2026 / Story
0
#4 The Hacker News general September 22, 2026 at 18:03 UTC

WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers

By [email protected] (The Hacker News)

AI Summary

WordPress shipped version 7.1.2 on September 22 to fix a critical unauthenticated RCE flaw allowing attackers to load arbitrary PHP files outside theme directories. The patch covers all supported branches back to version 4.7, and on vulnerable server configurations the flaw can lead to full code execution without any account. Site administrators should update immediately given the breadth of affected installations.

Relevance score: 88.0/100

# More from September 23