Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
How Sandboxing Closes the Phishing Detection Visibility Gap
September 23, 2026
Critical cPanel Vulnerability Exposes User Accounts
September 23, 2026
Outerlimit Raises $16M to Secure AI Agents with Zero Trust
September 23, 2026
Home/CyberSecurity News/Critical WordPress Core RCE Vulnerability CVE-2023-45123 Patched
CyberSecurity News

Critical WordPress Core RCE Vulnerability CVE-2023-45123 Patched

Key Takeaways WordPress has released version 7.1.2 to address a critical remote code execution (RCE) vulnerability. Tracked as CVE-2026-87902, the flaw could allow unauthenticated attackers to...

Jennifer sherman
Jennifer sherman
September 23, 2026 3 Min Read
5 0

Key Takeaways

  • WordPress has released version 7.1.2 to address a critical remote code execution (RCE) vulnerability.
  • Tracked as CVE-2026-87902, the flaw could allow unauthenticated attackers to execute arbitrary code on vulnerable websites.
  • The vulnerability affects the core WordPress page template resolution mechanism.
  • Immediate patching is strongly recommended for all WordPress installations, as unauthenticated exploitation is possible under specific conditions.

Critical RCE Vulnerability Patched in WordPress Core

WordPress has rolled out a crucial security update, version 7.1.2, to mitigate a severe vulnerability that could enable unauthenticated attackers to execute arbitrary code on affected websites. Site administrators are urged to apply this patch without delay, as successful exploitation of this flaw does not necessitate an attacker to possess valid login credentials or a WordPress account.

Table Of Content

  • Key Takeaways
  • Critical RCE Vulnerability Patched in WordPress Core
  • Understanding CVE-2026-87902
  • Implications of Remote Code Execution
  • Patching and Mitigation
  • What You Should Do

Understanding CVE-2026-87902

Designated as CVE-2026-87902, this critical vulnerability resides within WordPress’s page template resolution process. This fundamental mechanism dictates which PHP template file is utilized to render a requested page on a WordPress site. Security researcher Robert Ressl is credited with the responsible disclosure of this issue to the WordPress security team.

The flaw essentially allows a remote attacker to manipulate the template resolution logic, potentially causing WordPress to include a local PHP file from an unauthorized location outside of the active theme directory. Normally, WordPress is designed to load page templates exclusively from trusted theme paths. This vulnerability creates an illicit pathway, enabling an attacker to force the inclusion of a local PHP file that should not be accessible through the standard theme rendering process.

Implications of Remote Code Execution

If specific server configurations and the active WordPress theme meet certain preconditions, the inclusion of a chosen local PHP file can culminate in remote code execution (RCE). This means a malicious actor could potentially run arbitrary PHP code on the underlying web server without needing to authenticate to the WordPress site itself.

RCE vulnerabilities represent one of the most severe threats to content management systems. A successful attack could grant threat actors extensive control, allowing them to deploy web shells, exfiltrate sensitive database credentials, deface website content, create unauthorized administrator accounts, redirect site visitors to malicious pages, distribute malware, or even leverage the compromised server as a pivot point for further attacks on other systems.

While the security release notes do not indicate that every WordPress installation is immediately exploitable, the potential for RCE is contingent on factors such as the server environment, the active theme in use, and the presence of readable PHP files outside the designated active theme directories. Nevertheless, the unauthenticated nature of the attack vector makes exposed and unpatched sites prime targets for automated internet scanning and opportunistic exploitation by threat actors.

Patching and Mitigation

WordPress strongly advises all administrators to update their sites to version 7.1.2 immediately. The latest package can be downloaded directly from the official WordPress website, or the update can be installed via the WordPress Dashboard by navigating to “Updates” and clicking “Update Now.” Sites configured for automatic background updates may receive the patch without manual intervention.

The fix for this vulnerability has also been backported to older WordPress branches that are still eligible for security updates, currently extending back to version 4.7. While this provides a mitigation path for legacy deployments, WordPress emphasizes that only the latest release is actively supported and receives ongoing maintenance.

Organizations operating public-facing WordPress sites should treat CVE-2026-87902 as an urgent patching requirement. The combination of unauthenticated access and the potential for remote code execution necessitates rapid remediation to prevent full site and server compromise.

What You Should Do

  • Update Immediately: Upgrade all WordPress installations to version 7.1.2 without delay.
  • Verify Updates: Confirm that all sites are running a patched release after the update process.
  • Review Logs: Scrutinize web server and WordPress logs for any suspicious requests involving template paths, unexpected PHP execution, or newly created administrative users.
  • Inspect Custom Code: Review active themes and any custom code that modifies template selection behavior for potential vulnerabilities or unintended side effects.
  • Implement Defense-in-Depth: Ensure other security measures, such as web application firewalls (WAFs) and endpoint detection and response (EDR) solutions, are in place and up-to-date.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitMalwarePatchSecurityThreatVulnerability

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

New AI Malware Chooses Next Attack Steps, No Human Input Needed

Next Post

Critical ManageEngine Vulnerability Allows SYSTEM Access via Windows Login

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical AWS Lambda Flaw Bypasses IAM, Exposes Cloud Services
September 23, 2026
Critical Next.js CVE-2024-XXXXX RCE Flaw Lets Attackers Use SVG Files
September 23, 2026
New Malware Uses Evasive Domain Tactics to Hide Infrastructure
September 23, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us