Urgent.News

What's breaking now, across thousands of outlets.

Tech

What the WordPress 4.7.0 to 7.1.1 file inclusion bug teaches about patch windows

What the WordPress 4.7.0 to 7.1.1 file inclusion bug teaches about patch windows WordPress 7.1.2 was released on 22 September 2026 to fix a remote file inclusion flaw tracked as CVE-2026-87902. The interesting part of this event is not the vulnerability class. It is the timeline. Attack attempts were observed within hours of the patch, and the fix was back-ported to every maintained branch going…

The WordPress version 4.7.0 to 7.1.1 file inclusion bug highlights the importance of prompt patching. Released on September 22, 2026, the patch addressed a remote file inclusion vulnerability, tracked as CVE-2026-87902, observed within hours of its release. An unauthenticated attacker can manipulate the page template resolution logic, including a local PHP file from outside the active theme directory.

For this to lead to code execution, the active parent or child theme must contain a top-level directory starting with 'page-' and the server must host a reachable PHP file readable by the web service account. Public analysis notes two preconditions: the presence of a 'page-' directory and the server's ability to read a target PHP file.

Honeypot networks recorded 68 exploitation attempts against this flaw, with early requests originating from New Jersey and later traffic from Indonesian ranges. Attackers probed harmless core files first before moving to PEAR installation paths, indicating a reconnaissance-into-exploitation sequence. The patch window for this vulnerability was effectively zero, as the first recorded attempt appeared on the same day the patched version was released.

Automated scanners and exposed WordPress sites contribute to the vulnerability's rapid exploitation. Mitigations include blocking path traversal patterns at the web application firewall, disabling 'register_argc_argv' in PHP configuration, and auditing themes for 'page-' directories. Automatic background updates, theme checks, and temporary directory monitoring are recommended for defenders to reduce their exposure.

This incident underscores the importance of timely patching, monitoring, and maintaining WordPress installations.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Your Cloud Bill Is a Design Document

Cloud spend is usually treated as a finance problem. Engineering gets the message after the fact: “Why did the AWS bill go up again?” But the bill is rarely just a bill.

  • Cloud bills reveal system architecture decisions
  • Every recurring charge reflects infrastructure choices
  • Cloud costs can provide valuable engineering data

Promotion - Database Replication

This is the critical system design. As it needs to provide redundancy , scalability and fault tolerance . It tells the replication between primary database and its replicas.

  • Synchronous replication provides strong data consistency by replicating changes in real-time.
  • Asynchronous replication improves transaction processing speed but may compromise data consistency.

More from Saturday 3 October →