Latest news and offers

Critical WordPress Security Update: Upgrade Your Website Now

Critical WordPress Security Update: Upgrade Your Website Now

A critical security vulnerability has been identified and patched in WordPress Core. If your website uses WordPress, you should update it immediately and confirm that the upgrade has completed successfully.

What has happened?

The issue, tracked as CVE-2026-87902, is an unauthenticated path traversal vulnerability with a critical CVSS score of 9.2. It could allow an attacker to make a vulnerable WordPress site include a readable PHP file from outside its active theme directory. Under certain theme and server conditions, this could lead to remote code execution and complete compromise of the website.

An attacker does not need a WordPress account, password or any interaction from a website administrator to attempt exploitation. Although successful exploitation depends on the site’s theme structure and server environment, the vulnerable behaviour is within WordPress Core, so site owners should not assume they are safe based on the theme they use.

What should you do?

  • Update WordPress immediately. Upgrade to WordPress 7.1.2, or install the fixed security release available for your current WordPress branch.
  • Confirm that the update completed successfully. Check the WordPress dashboard and verify the installed version.
  • Back up before making changes. Take a current backup of your website files and database before upgrading.
  • Test your website after the update. Check key pages, forms, login areas and any important customer journeys.
  • Update plugins and themes. Apply available updates and remove any extensions or themes that are no longer required.

Do not rely on firewall protection alone

A web application firewall can help reduce exposure, but it is not a replacement for installing the WordPress security update. Wordfence advises that its Premium, Care and Response customers received a protective firewall rule on 22 September 2026, while Wordfence Free users are due to receive the same protection on 22 October 2026. Updating WordPress Core remains the recommended fix.

Check your update today

Even if automatic updates are enabled, sign in to your WordPress dashboard and verify that the patched version is installed. If your website is managed by a developer or agency, contact them now and ask them to confirm that the security update has been applied and tested.