News
WordPress patches critical unauthenticated path traversal flaw CVE-2026-87902 Correction
WordPress released a patch on September 22 for CVE-2026-87902, a critical unauthenticated path traversal flaw. Every branch from 4.7.0 through 7.1.1 needs updating, including the 7.1.1 release from September 17.