Behind the Screen - A Blog

Critical WordPress Security Update 2026 | John Corner

If you run a WordPress website for your small business, you need to pay close attention to your dashboard today. On the 22nd of September 2026, a highly critical security vulnerability was disclosed that affects almost all versions of WordPress core.

Attackers are already scanning the web for vulnerable sites. Because small and medium businesses often delay routine maintenance, they are prime targets for automated attacks like this.

The Technical Details (Simplified)

Tracked by security researchers as CVE-2026-87902, this issue is known as an "unauthenticated path traversal" vulnerability.

In plain terms, this means an attacker does not need an account, a username, or a password to attack your site. They do not need to trick you into clicking a phishing link. By sending a specifically crafted web request, an attacker can manipulate how WordPress searches for page templates.

If your active theme has a specific folder layout (such as a directory starting with "page-") and your server environment meets certain criteria, the attacker can force your website to run malicious PHP code. This can rapidly lead to remote code execution, resulting in a complete site takeover.

Why This is a Major Threat

What makes this particularly dangerous is that it is a flaw in the core WordPress software itself, not a poorly coded third party plugin. The official advisory noted that several popular themes possess the exact directory structure needed for an attacker to exploit this bug. Relying on a firewall offers some protection, but it is not a substitute for patching the root cause.

What You Need To Do Right Now

  1. Log in to your WordPress dashboard.
  2. Navigate to Dashboard > Updates.
  3. Check your current version. WordPress 7.1.2 contains the official fix.
  4. If your site has not updated automatically, click to install the latest security release immediately.

Please note that WordPress has also released security backports for older branches (going all the way back to version 4.7), so even if you are on an older version, a patch is available.

Need Help Securing or Cleaning Your Site?

Keeping on top of technical updates can be overwhelming when you are busy running your business.

If you are unsure how to apply these updates safely without breaking your site, or if you suspect your website has already been compromised and requires a professional deep clean to remove malware, please get in touch. Based locally in Teesside, I can help audit your site, clean up any compromised files, and lock down your digital presence so you can get back to business.

Visit the contact page to secure your site today.