WordPress 7.1.2 Patches Critical Unauthenticated Remote Code Execution Vulnerability

The WordPress security team released WordPress 7.1.2 on September 22, 2026, patching a critical vulnerability in the core page template loading logic. Under certain server and theme configurations, the flaw allows an unauthenticated attacker to execute arbitrary PHP code on…









