Somebody Has to Patch the Website

WordPress shipped an emergency security release on September 22. Attackers were scanning for sites that hadn't taken it the same morning. Five minutes tells you whether yours is one of them.

On September 22, WordPress released version 7.1.2. It fixes exactly one thing, and it's the kind that gets a release of its own: a flaw letting a stranger with no account make your site open a file it was never meant to touch. By that same morning, attackers were scanning for sites that hadn't taken it. By the next day the probing was ten times higher, from a few hundred addresses. That's the part worth sitting with. Not the flaw — the speed. For transparency, and because it cuts against us: we don't build or host websites. It's here because a website is business software, and business software nobody patches is the same problem whoever owns it. The technical part — you can skip this box WordPress 7.1.2, released September 22, 2026, a security-only release. Reported by Robert Ressl. It fixes an unauthenticated path traversal in page-template resolution that can become conditional remote code execution: get_page_template() can be made to include a chosen readable local .php file from outside the active theme directories. Versions 4.7 through 7.1.1 are the affected ones; 7.1.2 carries the fix , and it has been backported down every supported branch — 7.0.6, 6.9.9, 6.8.10, 6.7.9 and so on to 4.7.37. WordPress 4.6 and earlier get nothing. Tracked as CVE-2026-87902, rated 9.2 Critical on CVSS version 4 — note that the identifier and score come from Patchstack and Help Net Security, not from WordPress's own release note, which assigns neither. Patchstack's research sets out the two conditions required to reach code execution rather than information disclosure: a top-level directory beginning page- inside the active theme, and PHP's register_argc_argv enabled, which exposes the query string to the included script and allows the PEAR pearcmd.php escalation chain. Observed attacks write .php files into /tmp and /var/tmp . What that actually means "Path traversal" is talking a program into stepping outside the folder it is supposed to stay in. The website is meant to open page templates from its own theme folder. This lets someone point it somewhere else on the server. "Conditional" is doing real work there. Two server settings have to line up before this goes from leaking a file to running code you didn't write . Most sites won't have both. You can't tell from outside which you are — and neither can the person scanning you, which is why they scan everyone. Which way the version numbers run. Anything older than 7.1.2 is exposed; 7.1.2 and newer is fixed. On an older branch, the backport number for that branch is the fix. Bigger is safer. The reassuring part, and it's real WordPress installs its own security releases. If nobody turned that off, your site has very likely already taken this one without anyone lifting a finger. That is the system working. The part that isn't Somebody turned it off on a great many sites. Usually an agency, years ago, because an update once broke a layout at a bad moment and leaving them off felt safer. Then the contract ended, the agency moved on, and nothing has updated itself since. And plenty of small businesses aren't on WordPress at all — Squarespace, Wix and Shopify patch themselves, and you have nothing to do here. Knowing which you are is the whole exercise. What to do, and it's about five minutes Log in to your site's admin area — it's usually your address with /wp-admin on the end. Open Dashboard → Updates . It tells you the version and whether anything is waiting. If it says 7.1.2, or the backport number for your branch, you're done. If nobody at your company can log in, stop. That's the finding, and it's a bigger one than this month's flaw. Someone has your website's keys and it isn't you. If you use an outside web person, one email: "Are we on WordPress 7.1.2 or the backport for our version, and are automatic updates on?" If the reply takes a week, you've learned something about that arrangement this month's flaw was never going to teach you.