CuraSec

Plan active

WordPress 7.1.2 Patches Critical Unauthenticated RCE in Core

2026-09-23 15:27 UTC · The Hacker News · read the source ↗ #wordpress#rce#patch
  • Engineer — Plan: Unauthenticated PHP file inclusion enabling potential code execution is severe and affects all WordPress branches back to 4.7; no KEV listing or public PoC in signals, but the attack surface is enormous — patch to WordPress 7.1.2 across all managed sites within your normal critical-patch window.
  • SOC/IR — Skip
  • Leader — Skip
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.