WordPress 7.1.2 Fixes a Remote Code Execution Flaw Days After the 7.1.1 Security Release
WordPress shipped two security releases in the space of five days in September 2026. WordPress 7.1.1 arrived on September 17 with a batch of security and bug fixes, and WordPress 7.1.2 followed on September 22 to close a single, more serious flaw that the project says can lead to remote code execution under certain conditions.
If your company website runs on WordPress, this is a maintenance item that should not wait for the next scheduled update window. Whether you manage the site in-house or through a WordPress development partner, the question to answer this week is simple: which version is each of your sites running right now?
This article explains what the two releases fixed, how to tell whether you are covered, and what a sensible response looks like for a business that depends on its website.
What WordPress released, and when
On September 17, 2026, the WordPress project published the WordPress 7.1.1 maintenance and security release. According to that announcement, it contains 11 security fixes together with 17 bug fixes in Core and 19 bug fixes for the Block Editor.
On September 22, 2026, the project published the WordPress 7.1.2 release, a security release addressing one vulnerability in how WordPress resolves page templates. The announcement recommends updating sites immediately.
Both releases are available now. Neither is a preview or a beta. The only forward-looking item in the two announcements is the next major version: the 7.1.1 post says WordPress 7.2 is currently planned for December, which is a plan rather than a commitment.
The flaw fixed in WordPress 7.1.2
The 7.1.2 announcement describes the issue this way: an attacker who is not logged in can, under certain conditions, cause page template resolution to include a readable local PHP file from outside the active theme directories. The announcement adds that when the relevant pre-conditions are met for both the server environment and the active theme, this can lead to remote code execution. It references the issue as CVE-2026-87902 and credits Robert Ressl for responsible disclosure.
In plain terms, remote code execution means an outsider can run their own commands on your web server. That is the most damaging class of website vulnerability, because it can be used to read the database, alter pages, plant malicious redirects or use the server to attack others.
Two details in the wording matter. First, the attacker does not need an account, so hiding the login page or enforcing strong passwords does not help. Second, exploitation depends on conditions in the server setup and the theme. The announcement does not spell those conditions out, so a site owner cannot reliably conclude from the outside that a particular site is safe. Updating is the only dependable answer.
What WordPress 7.1.1 fixed five days earlier
The 7.1.1 announcement lists its 11 security fixes individually. They are a mix of issues that affect anonymous visitors and issues that require a logged-in account. Examples from the announcement include:
- A stored cross-site scripting issue that could be triggered through comments, subject to comment approval.
- A flaw where a specially crafted URL could install and preview an inactive theme.
- A path traversal issue in the REST API templates controller that requires authentication.
- Several authorization gaps that let lower-privileged users, such as Contributors, overwrite posts or see titles and slugs of content they should not have access to.
Many of these matter most on sites with multiple user accounts: membership sites, publications with outside contributors, multisite networks and stores with staff logins. A brochure site with one administrator has less exposure to the account-based issues, but is still exposed to the comment-based one if comments are enabled.
Which sites are affected
Neither announcement names the first affected version. What they do say is that the fixes were backported to every branch still eligible for security fixes, which the 7.1.2 post states is currently back to WordPress 4.7. The practical reading, offered here as guidance rather than as a statement from WordPress, is that a site on any older branch should be assumed to need the corresponding patched release for that branch.
Both announcements also repeat an important caveat: only the most recent version of WordPress is actively supported. Backported fixes are a courtesy for sites that cannot move immediately. They are not a reason to stay on an old branch indefinitely.
Sites that have automatic background updates enabled will, according to the announcements, update on their own. Sites where automatic updates have been switched off, which is common on customized or heavily integrated builds, will not.
What this means for your business
For most small and mid-sized organizations, the direct risk is not the vulnerability itself but the gap between a fix being published and the fix being installed. Once a security release is public, the code change is visible to everyone, including people who look for unpatched sites. The shorter that gap, the lower the exposure.
Two releases in five days also tests a process that many companies have never written down. If your answer to "who updates WordPress, and how quickly?" is unclear, this is a good moment to settle it. A site on a managed host with automatic minor updates may already be patched. A site on a self-managed server with updates disabled, maintained by an agency that is no longer under contract, probably is not.
For businesses in the United States and the United Kingdom that collect personal data through forms, accounts or checkout, keeping software patched is also part of meeting general security expectations under data protection rules. This article is not legal advice, and obligations vary by sector and jurisdiction.
What to do next
The steps below are practical guidance and apply to almost any WordPress site.
- Check the version. In the WordPress dashboard, the Updates screen shows the installed version. Sites on the 7.1 branch should be on 7.1.2.
- Update now if you are behind. The announcement points to the Updates screen in the dashboard or a download from WordPress.org. Take a backup first, and on complex sites test on a staging copy.
- Confirm whether automatic updates are enabled, and if they are disabled, record who is responsible for applying security releases and how fast.
- If a site is stuck on an old branch because of an outdated theme or plugin, apply the backported release for that branch and plan the work needed to return to the current version.
- Review user accounts. Several of the 7.1.1 fixes relate to what Contributor-level and other logged-in users can do, so removing unused accounts reduces exposure in general.
Plugins and themes are updated separately from WordPress core, so it is worth checking those on the same visit. Because the 7.1.2 issue depends partly on the active theme, an unmaintained or heavily modified theme deserves a closer look from a developer.
Why two releases so close together
The announcements do not explain the timing, and it would be speculation to fill that in. What can be said is that a short, single-fix release issued days after a larger one is a normal pattern in software maintenance: a serious report is handled on its own schedule rather than held for the next planned release.
For site owners, the lesson is about process. Applying 7.1.1 on September 17 did not finish the job. Anyone who updates manually needs a way to hear about the next release as well, whether through the WordPress news feed, a hosting provider's notices or a maintenance agreement.
Conclusion
WordPress 7.1.1, released on September 17, 2026, fixed 11 security issues, and WordPress 7.1.2, released on September 22, 2026, fixed a flaw that can lead to remote code execution without a login when certain server and theme conditions are met. Both are available now, fixes have been backported to older supported branches, and the WordPress project recommends updating immediately.
If you are unsure which version your site is running, or an older theme or plugin is blocking the update, get in touch with Entrant Technologies and we can help you assess the site and plan the update.