WordPress Just Patched a Critical Bug That Was Already Being Exploited

WordPress 7.1.2 closes a critical vulnerability tracked as CVE-2026-87902, the fifth core security release since July. Researchers reported active probing within hours of the patch going public, so updating now matters more than usual.

Get a summary in:
Lines of code displayed on a computer screen representing a security patch
Follow Teck Hustlers on Google
Add Teck Hustlers as a preferred source to see more of our stories in Google Top Stories.
Add as preferred source on Google

AA Admin Alex
Writer
MA M.Ali
Fact-Checker
FB X IG in TT P

Published: October 7, 2026 · Last updated: October 7, 2026

TL;DR: WordPress 7.1.2 is out, it closes a critical vulnerability, and it’s the fifth security release since July. Early reports suggest attackers were already probing for the bug before most site owners had even seen the update notice.

Abstract cybersecurity image representing a software patch
Photo via Unsplash

If you run a WordPress site and haven’t logged into wp-admin this week, do it before you finish this paragraph. WordPress 7.1.2 shipped as a security-only release, and the WordPress security team rated the underlying flaw critical, not the usual “update when convenient” language reserved for minor bugs.

The project’s own account on X put it plainly:

“WordPress 7.1.2 is now available. This security release fixes a critical vulnerability. Update your sites immediately from Dashboard > Updates, and read the release details,” the official WordPress account posted.

The vulnerability is tracked as CVE-2026-87902, and it matters because of where it sits, not just what it technically allows. Researchers who reviewed the patch say it touches core authentication handling, the part of WordPress that decides whether a request is actually coming from someone logged in. Get that wrong and an attacker doesn’t need to guess a password. They just need a server that hasn’t patched yet.

This is the fifth core security release WordPress has shipped since July, which is a lot even by WordPress’s own historically busy patch cadence. 7.1 arrived in August with a promise of better editing and a more sensible approach to security. 7.0.3 patched a dozen issues including a high-severity login cross-site scripting bug, and that one was reportedly being probed within days of release too. Now 7.1.2 follows the same pattern.

None of that is necessarily a red flag by itself. A platform running a huge share of the web attracts more scrutiny, and more scrutiny finds more bugs. What should worry site owners is the gap between disclosure and exploitation. Security researchers tracking this CVE reported signs of active probing within hours of the patch going public, the exact window attackers use to hit sites before admins get around to clicking update. WordPress’s auto-update system catches a lot of this automatically, but plenty of hosts and site owners still have it disabled, usually because a plugin broke during an automatic update years ago and nobody ever turned the setting back on.

If you run an agency, manage client sites, or just keep your own blog running, the move is simple. Check your WordPress version right now, and if it isn’t 7.1.2, update before doing anything else today. Then check your plugins, because a patched core doesn’t help much if an outdated plugin has its own hole sitting wide open.

Related: Chrome’s seventh zero-day of the year and Google’s September spam update results.

Bottom Line: This isn’t a patch-when-you-get-a-chance update. Attackers were already poking at it before most admins saw the notice, and a platform this widely used means automated scanners will be hitting unpatched sites within days. Update now, check your plugins next.

Follow Teck Hustlers: Facebook · X · Instagram · LinkedIn · TikTok · Pinterest

]]>

Follow Teck Hustlers on Google
Add Teck Hustlers as a preferred source to see more of our stories in Google Top Stories.
Add as preferred source on Google