Skip to main content

WordPress 7.1.2 Security Release now available

September 22, 2026

The latest security release for WordPress, 7.1.2, is available on Pantheon.

Action required

Because this is a security update, we recommend all users upgrade to WordPress 7.1.2 as soon as possible from your Pantheon dashboard or Terminus to access the latest features, fixes, and security enhancements. See related documentation for how to apply core updates.

Pantheon has pre-deployed platform-wide mitigations (virtual patching via our routing network) against external abuse of this vulnerability (CVE-2026-87902), and is actively monitoring those rules. However, customers need to update their sites as soon as possible.

Highlights

This release resolves one critical severity vulnerability (CVE-2026-87902) that does not require authentication to exploit. Under certain server and theme conditions, an unauthenticated attacker can cause page template resolution to include a chosen readable local PHP file outside the active theme directories, which could potentially lead to remote code execution.

For full details, see the WordPress 7.1.2 release notes and WordPress documentation.