# WordPress patches RCE flaw in 7.1.2

Published: 2026-09-23 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/6a783ae0-01fc-5281-b925-3800465eeda8/wordpress-patches-rce-flaw-in-7-1-2

> CERT-FR advisory warns of a remote code execution vulnerability in WordPress versions before 7.1.2; patch now.

CERT-FR issued an advisory regarding a vulnerability in WordPress affecting all versions prior to 7.1.2. The flaw, tracked as CVE-2026-87902, allows an attacker to achieve remote code execution, though the advisory does not specify the attack vector, authentication requirements, or whether exploitation has been observed in the wild. WordPress addressed the issue in its official 7.1.2 security release published on 22 September 2026, alongside a corresponding GitHub security advisory (GHSA-7hp8-65ch-5whp).

Defenders running WordPress should prioritize updating to version 7.1.2 or later immediately, given the severity of remote code execution and the widespread deployment of WordPress across web infrastructure. No indicators of compromise, exploitation details, or threat actor attribution were provided in this advisory. Organizations should consult the referenced WordPress and CVE documentation for further technical details and verify patch deployment across all managed WordPress instances.

## Mentioned in this report

- Vulnerabilities: CVE-2026-87902

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1216

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/6a783ae0-01fc-5281-b925-3800465eeda8/wordpress-patches-rce-flaw-in-7-1-2.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
