Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

WordPress 7.1.2 Release

Дата публикации: 22-09-2026 14:01:20

This security release features a fix for a critical severity security vulnerability. Because this is a security release, it is recommended that you update your sites immediately. You can download WordPress 7.1.2 from WordPress.org, or visit your WordPress Dashboard, click “Updates”, and then click “Update Now”. If you have sites that support automatic background updates, […]

Основное содержимое страницы с новостью.


This security release features a fix for a critical severity security vulnerability.

Because this is a security release, it is recommended that you update your sites immediately.

You can download WordPress 7.1.2 from WordPress.org, or visit your WordPress Dashboard, click “Updates”, and then click “Update Now”. If you have sites that support automatic background updates, the update process will begin automatically.

Security update included in this release

The security team would like to thank Robert Ressl for responsibly disclosing that an unauthenticated attacker can, under certain conditions, make page template resolution include a chosen readable local PHP file outside the active theme directories. If relevant pre-conditions for both the server environment and the active theme are met, this can lead to remote code execution (RCE).

Thank you to these WordPress contributors

This release was led by John Blackbourn. WordPress 7.1.2 would not have been possible without the contributions of the following people:

Aaron Jorbin, Aki Hamano, Alex Concha, Ehtisham Siddiqui, fiocavallari, Jb Audras, Jeffrey Paul, Jeremy Felt, Joe McGill, John Blackbourn, Jon Surrell, Lance Willett, Manuel Camargo, marcs0h, martin.krcho, Mukesh Panchal, Olga Gleckler, Pascal Birchler, Peter Wilson, Rajin Sharwar, Ressl, Rudy Faile, Sergey Biryukov, Shail Mehta, Stephanie Walters, and vortfu.

CVE and GHSA references

Further details can be found in the advisory: CVE-2026-87902 / GHSA-7hp8-65ch-5whp.

Backports

As a courtesy, the security fix was backported to all branches eligible to receive security fixes (currently through 4.7). As a reminder, only the most recent version of WordPress is actively supported.

Share this:

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1WordPress 7.1.3 Maintenance and Security Release09.3706-10-2026
2WordPress 7.1.1 Maintenance and Security Release010.7717-09-2026
3OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted08.3130-09-2026
4security/boringssl - 0.20260929.0015.6202-10-2026
5security/s2n-tls - 1.7.11,1017.102-10-2026
6Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link011.5426-09-2026
7security/x11appjail - 1.2.0017.0702-10-2026
8Kiteworks Fixes Critical Flaw Found During Nine-Hour Precautionary Shutdown07.3129-09-2026
9В десктопной версии Telegram выявили позволяющую красть файлы уязвимость-17.8809-10-2026
10[0day-rubbish] Advantech WebAccess Node 9.2.3 unauthenticated CrystalRpt.aspx file upload and path traversal to code execution in w3wp.exe (9.8)010.4106-10-2026

Классификация: . Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 8.04. Источник: wordpress.org.