WordPress Core Unauthenticated Path Traversal Affects Every Version Since 2016, Can Enable Code Execution (CVE-2026-87902)
Scope: WordPress Core, All Versions 4.7.0 Through 7.1.1
Severity: Red
WordPress released an emergency patch for CVE-2026-87902, a critical unauthenticated path traversal vulnerability rated CVSS 9.2, that reaches every WordPress version from 4.7.0 through 7.1.1, meaning even a site updated to last week's September 17 security release, 7.1.1, still needs this separate fix. The flaw requires no account and no action from a logged-in user, and allows an attacker to load local PHP files through a crafted path. On some server configurations, this loading behavior can be escalated into full code execution rather than simple file exposure. WordPress does not offer a configuration-based workaround, so updating is the only fix, and the company has backported the patch down to version 4.7.37 to cover as many legacy installations as possible. WordPress powers a significant share of government, education, and business websites in Uganda, making this one of the broadest reaching advisories of the month for the local web ecosystem. Sites with automatic background updates enabled will receive the fix without action, while sites managed manually or by a developer need to update from the WordPress dashboard under Updates, or download the release directly from WordPress.org today.
The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.