WordPress Ships a Critical Patch, No Login Needed to Exploit It

A plain grey door standing ajar in a bone-cream wall, a thin sliver of near-black green-tinted space showing through the gap, with a single flat key lying on the step below rendered solid acid green.

WordPress released version 7.1.2 on 22 September, five days after its last update, this time for a single flaw its own security team rated critical: under certain conditions, an unauthenticated visitor could make the site load a chosen file from outside its active theme, a route that can end in running code on the server. WordPress's own release announcement says update immediately, the same instruction as last week. The risk behind it isn't the same.

Last week's release needed an existing account before anything happened: a contributor overwriting someone else's draft, seeing a private post's title, installing a theme through a crafted link. This one doesn't. Nobody needs to be logged in at all, and that's the detail that earns it the critical label rather than the routine run of fixes a maintenance release usually carries.

Whether a site has already picked up the fix depends on the same setting as before. Most hosts leave WordPress's background updates switched on, so plenty of sites will already be running 7.1.2 without anyone doing anything. Where that setting is off, or a plugin or a cautious host has turned it off, the update sits in the WordPress Dashboard's Updates screen until somebody clicks it. That screen names the version currently running. Two minutes there settles the question either way, and two minutes now beats clearing up after a site that's quietly been rewritten by someone else.

Two security releases inside a week is unusual even for WordPress. The advisory tracking this one, CVE-2026-87902, flags it as exploitable without any account at all, which is the line worth reading twice on a site nobody has checked the Updates screen on in a while.

Whoever is meant to be watching for a release like this one is worth settling before it matters, not after, the same starting point as this guide on keeping a small site secure. Every site we build runs on the £69 a month care plan, which covers exactly this kind of update alongside hosting and backups, so a second release five days after the first would not be something you needed to notice at all. See what that looks like if patch days are not how you want to spend an afternoon.

Your website is one form away.

Tell us your business name and your town. We build the site, you preview it from your inbox, and the invoice waits for the yes.