Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11The lesson from CVE-2026-87902 is to patch by branch, not by guessing from a recent version number: WordPress 7.1.1 is affected, 7.1.2 is the listed fix for the 7.1 branch, and older branches have their own fixed point releases as far back as 4.7. The flaw is reachable without authentication, but the advisory’s path to remote code execution depends on additional theme and server conditions.
What the WordPress file-inclusion bug does
The WordPress/wordpress-develop advisory tracks the vulnerability as CVE-2026-87902 and classifies it as CWE-98, improper control of a filename used in a PHP include or require statement. It credits Robert Ressl as the discoverer and responsible discloser.
In the documented path, an unauthenticated attacker can influence get_page_template() resolution so that WordPress includes a chosen readable local .php file outside the active theme directories. The advisory rates the vulnerability Critical and gives it a CVSS v4 overall score of 9.2/10. Its vector lists a network attack, low attack complexity, present attack requirements, no privileges required, and no user interaction.
File inclusion is the direct flaw; remote code execution is a conditional outcome, not an automatic result on every affected installation. The advisory’s stated theme and server prerequisites matter when assessing that route. The unauthenticated network reachability and Critical rating still make the core fix the priority.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →#1 Best Overall
Which WordPress versions are affected, and what fixes each branch?
The WordPress/wordpress-develop 2026 advisory lists these affected ranges and branch-specific fixed releases. Compare the complete installed version with the row for its branch; a release immediately before the fixed point release remains affected.
| Branch | Affected releases | Fixed release listed |
|---|---|---|
| 7.1 | 7.1.0–7.1.1 | 7.1.2 |
| 7.0 | 7.0.0–7.0.5 | 7.0.6 |
| 6.9 | 6.9.0–6.9.8 | 6.9.9 |
| 6.8 | 6.8.0–6.8.9 | 6.8.10 |
| 6.7 | 6.7.0–6.7.8 | 6.7.9 |
| 6.6 | 6.6.0–6.6.8 | 6.6.9 |
| 6.5 | 6.5.0–6.5.11 | 6.5.12 |
| 6.4 | 6.4.0–6.4.11 | 6.4.12 |
| 6.3 | 6.3.0–6.3.11 | 6.3.12 |
| 6.2 | 6.2.0–6.2.12 | 6.2.13 |
| 6.1 | 6.1.0–6.1.13 | 6.1.14 |
| 6.0 | 6.0.0–6.0.15 | 6.0.16 |
| 5.9 | 5.9.0–5.9.17 | 5.9.18 |
| 5.8 | 5.8.0–5.8.16 | 5.8.17 |
| 5.7 | 5.7.0–5.7.18 | 5.7.19 |
| 5.6 | 5.6.0–5.6.20 | 5.6.21 |
| 5.5 | 5.5.0–5.5.21 | 5.5.22 |
| 5.4 | 5.4.0–5.4.22 | 5.4.23 |
| 5.3 | 5.3.0–5.3.24 | 5.3.25 |
| 5.2 | 5.2.0–5.2.27 | 5.2.28 |
| 5.1 | 5.1.0–5.1.25 | 5.1.26 |
| 5.0 | 5.0.0–5.0.28 | 5.0.29 |
| 4.9 | 4.9.0–4.9.32 | 4.9.33 |
| 4.8 | 4.8.0–4.8.31 | 4.8.32 |
| 4.7 | 4.7.0–4.7.36 | 4.7.37 |
Why the exploit depends on the site’s configuration
The advisory describes a specific path to the flaw, with two relevant conditions:
- Theme directory: The active parent or child theme has a top-level directory whose name begins with
page-;page-templatesis the advisory’s example. It names Twenty Twelve, Twenty Fourteen, Neve, Hestia, and Sydney as examples of themes to consider, but that is not a claim that every installation or configuration of those themes meets the condition. - Readable local PHP target: A chosen
.phpfile exists on the server and is readable by the web-server account. The advisory discusses a possible PEAR-to-RCE transition viapearcmd.phpwhen PHP’sregister_argc_argvis On. It notes this setting in the official PHP Docker image and in the default cPanel configuration when PHP prior to 8.5 is used.
These requirements explain why the CVSS vector records attack requirements as present. They are not a reason to leave an affected core installation unpatched: they describe conditions in the documented exploitation route, not a substitute for the fixed release.
How to check and close the patch window
- Check the installed version. In the WordPress Dashboard, open Dashboard > Updates and note the installed WordPress version. If managing the site another way, use the version reported by that management system and confirm it against the site’s actual installation.
- Match the version to its branch. Find that branch in the table above. If the installed version is within its affected range, update to at least the fixed point release listed for that same branch. For example, 7.1.1 is not fixed; 7.1.2 is the listed 7.1 fix.
- Apply the core update. Use the available WordPress update in Dashboard > Updates or the site’s normal managed update process. WordPress documentation says supported automatic background updates begin automatically, but availability of an update is not proof that a particular site has installed it.
- Verify completion. After the update reports completion, check the installed version again and compare it with the branch’s fixed release. Record or monitor that final installed state rather than treating a published release, queued update, or successful-looking notification as confirmation by itself.
WordPress 7.1.1 illustrates why the release date alone is not enough. WordPress.org documented 7.1.1 on September 17, 2026 as a security and maintenance release, with 17 Core bug fixes, 21 Block Editor bug fixes, and 11 security fixes; its announcement recommended updating immediately because it was a security release. Those counts and that recommendation describe 7.1.1, not the later CVE-2026-87902 fix, which the advisory lists in 7.1.2. A security release can address important issues without containing a fix disclosed separately afterward.
Rank #3
What backports do—and do not—mean
The advisory lists fixes for maintained branches from 7.1 back to 4.7. This is useful operational coverage: a site that cannot immediately move to the newest branch may still have a corresponding point release that fixes this vulnerability. It does not mean every older WordPress release receives security fixes indefinitely.
WordPress.org’s Security policy says only the latest WordPress version is officially supported; the Security Team backports fixes to older versions as a courtesy so older sites can receive critical fixes through auto-updates. The 7.1.1 documentation likewise describes older-branch backports and says versions 4.6 and earlier no longer receive security updates. A backport closes this specific vulnerability on the listed branch when installed; it does not make that older branch officially supported or guarantee future security coverage.
Rank #4
What this advisory does not establish
The advisory and release information establish affected and fixed versions and describe a conditional exploitation path. They do not establish a defensible count of currently exposed sites, confirm exploitation in the wild, or provide a measured patch-adoption rate for CVE-2026-87902. WordPress.org’s statement that WordPress powers more than 43% of the web is platform-wide scale context, not a count of installations affected by this flaw.
A hosting provider or web application firewall may help coordinate a rollout or offer mitigation; WordPress describes coordination with hosting and security providers on releases and WAF mitigations. Neither should be treated as equivalent to installing the fixed core release named for the site’s branch.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

