HackerFeeds

CyberSecurity News

WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers

The Hacker News
· September 22, 2026

AI summary

WordPress has patched a critical vulnerability in its core software that allows an attacker without an account to load a PHP file from outside the theme folders. This flaw can potentially enable code execution on certain servers. The patch was released on September 22 as part of WordPress 7.1.2, and also includes fixes for older supported branches, dating back to version 4.7. WordPress is notifying site owners about the fix. The vulnerability can be exploited by an attacker with no account, making it a significant security concern. The patch is available for all supported versions of WordPress.

Read the full article at The Hacker Newsthehackernews.com/2026/09/wordpress-issues-patch-for-critical.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.