
WordPress has released an emergency security update addressing a critical vulnerability in its Core software that can allow an unauthenticated attacker to load arbitrary local PHP files and, under specific server and theme conditions, achieve remote code execution. Tracked as CVE-2026-87902, the vulnerability affects WordPress releases from version 4.7.0 through 7.1.1 and carries a CVSS […]
The post CVE-2026-87902: Critical WordPress Core Flaw Enables Unauthenticated RCE Under Certain Conditions appeared first on SOC Prime.