There was a problem loading the comments.

Critical WordPress Core Vulnerability (CVE-2026-87902): Action Required by Site Owners

Support Portal  »  Announcements  »  Viewing Article

  Print

Dear Customer,

 

On September 22, 2026, the WordPress Security Team published a critical security advisory affecting WordPress core. If you run WordPress on any SoftSys Hosting service, please read this notice and update your site(s) promptly.

 

What is the issue?
An unauthenticated attacker can manipulate the way WordPress resolves page templates. This makes WordPress load a readable local .php file from outside the active theme's directories. If certain conditions in the server environment and the active theme are met, this can escalate to remote code execution (RCE) on the website.

 

Severity: Critical (CVSS v4 score 9.2)
CVE: CVE-2026-87902
Advisory: https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp

 

Which versions are affected?
All WordPress versions from 4.7.0 through 7.1.1 are affected.

 

Which versions are fixed?
Update to the patched release for your branch:

 

Your branch Update to
7.1.x 7.1.2
7.0.x 7.0.6
6.9.x 6.9.9
6.8.x 6.8.10
6.7.x 6.7.9
6.6.x 6.6.9
6.5.x 6.5.12
6.4.x 6.4.12
6.3.x 6.3.12
6.2.x 6.2.13
6.1.x 6.1.14
6.0.x 6.0.16
5.9.x 5.9.18
5.8.x 5.8.17
5.7.x 5.7.19
5.6.x 5.6.21
5.5.x 5.5.22
5.4.x 5.4.23
5.3.x 5.3.25
5.2.x 5.2.28
5.1.x 5.1.26
5.0.x 5.0.29
4.9.x 4.9.33
4.8.x 4.8.32
4.7.x 4.7.37


We strongly recommend moving to the latest release (7.1.2) where your themes and plugins support it. Sites running a version older than 4.7 receive no fix and should be upgraded to a supported version without delay.

 

What you need to do

  1. Take a full backup of your site files and database.
  2. Log in to your WordPress admin and go to Dashboard → Updates, or update using WP-CLI (wp core update).
  3. Check the version shown under Dashboard → Updates or in the admin footer.
  4. Even if automatic background updates are enabled, check the version yourself. Auto-updates can be disabled by configuration, plugins or file permissions.
  5. If you manage multiple WordPress installations, repeat these steps for each one, including staging and development copies.

Scope of responsibility

SoftSys Hosting manages the server and hosting infrastructure only. The WordPress application (core, themes and plugins) and its updates are managed by the site owner or their developer. We will not update WordPress installations on your behalf, so please apply this update yourself or ask your developer to do it.

 

If you have questions about your hosting account, server access, backups or permissions needed to perform the update, please open a support ticket and our team will assist.

 

Regards,
SoftSys Hosting Support Team


Share via
Did you find this article useful?  

Related Articles

© Softsys Hosting