PSA: Critical Unauthenticated Path Traversal Vulnerability Patched in WordPress Core

On September 22, 2026, the WordPress Security Team released WordPress 7.1.2, as well as security backports for every branch back to WordPress 4.7 to address a critical unauthenticated path traversal vulnerability. The issue is tracked as CVE-2026-87902 and has a CVSS v4.0 score of 9.2 (Critical). The vulnerability can allow an unauthenticated attacker to make … Read more

WordPress 7.1.2 Release

This security release features a fix for a critical severity security vulnerability. Because this is a security release, it is recommended that you update your sites immediately. You can download WordPress 7.1.2 from WordPress.org, or visit your WordPress Dashboard, click “Updates”, and then click “Update Now”. If you have sites that support automatic background updates, … Read more

WordPress Takes Its Turn Leading the Open Website Alliance

I’m happy to announce that I am now serving as president of the Open Website Alliance (OWA), representing the WordPress Foundation. The Alliance brings together the community organizations behind Drupal, Joomla!, TYPO3, and WordPress to advocate for open source and share practices that benefit their projects. I represent the WordPress Foundation in this role, which … Read more

Wordfence Argus Discovers Critical Vulnerability in libheif, the Library That Opens iPhone Photos on Your Server

On September 1, 2026, the libheif project released version 1.23.3, closing a critical heap buffer overflow that the Wordfence Threat Intelligence team, using Wordfence Argus, discovered and reported four days earlier. The libheif maintainer, Dirk Farin, gave it a score of 9.8 out of 10 on the CVSS scale, with the release notes singling it … Read more