Return to Threats

WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers

thehackernews.com 2026-09-22 AI supply chain Critical

What Happened

WordPress has fixed a critical flaw in its core software that lets an attacker with no account make a site load a PHP file from outside its theme folders. On some servers, that can go further, allowing the attacker to run their own code. The fix shipped on September 22 in WordPress 7.1.2, with fixes for every branch the project still supports, back to 4.7, and WordPress is telling site owners

Why It Matters

WordPress 7.1.2 fixes CVE-2026-87902, a critical unauthenticated page-template resolution flaw that can cause a readable local PHP file outside the active theme directory to be included; under specific server and theme conditions, this may lead to remote code execution. The vulnerability affects WordPress versions 4.7.0 through 7.1.1, with patched releases issued across supported branches. This is not an AI-specific vulnerability, so its direct relevance to the allowed AI risk categories is low; RealGround analysis: organizations embedding AI services in WordPress should inventory affected components and apply the appropriate security update to reduce supply-chain exposure.

Healthcare Fintech SaaS SMB AI startups

RealGround Analysis

This signal maps to AI supply chain. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.

Recommended Actions

  • Restrict AI agent tool permissions and production write paths.
  • Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
  • Add human approval workflows for high-impact or state-changing actions.
  • Run prompt injection and indirect prompt injection tests against affected workflows.
  • Document the owner, control gap, and remediation deadline for this risk class.

Source

https://thehackernews.com/2026/09/wordpress-issues-patch-for-critical.html

Talk to AI CISO