{"id":2747,"date":"2026-09-22T14:01:20","date_gmt":"2026-09-22T14:01:20","guid":{"rendered":"https:\/\/mailurdu.co.uk\/?p=2747"},"modified":"2026-09-22T14:01:20","modified_gmt":"2026-09-22T14:01:20","slug":"wordpress-org-blog-wordpress-7-1-2-release","status":"publish","type":"post","link":"https:\/\/mailurdu.co.uk\/?p=2747","title":{"rendered":"WordPress.org blog: WordPress 7.1.2 Release"},"content":{"rendered":"<p class=\"wp-block-paragraph\">This security release features a fix for a critical severity security vulnerability.<\/p>\n<p class=\"wp-block-paragraph\"><strong>Because this is a security release, it is recommended that you update your sites immediately.<\/strong><\/p>\n<p class=\"wp-block-paragraph\">You can <a href=\"https:\/\/wordpress.org\/download\/\">download WordPress 7.1.2 from WordPress.org<\/a>, or visit your WordPress Dashboard, click \u201cUpdates\u201d, and then click \u201cUpdate Now\u201d. If you have sites that support automatic background updates, the update process will begin automatically.<\/p>\n<h2 class=\"wp-block-heading\">Security update included in this release<\/h2>\n<p class=\"wp-block-paragraph\">The security team would like to thank <a href=\"https:\/\/ressl.ch\/\">Robert Ressl<\/a> for responsibly disclosing that an unauthenticated attacker can, under certain conditions, make page template resolution include a chosen readable local PHP file outside the active theme directories. If relevant pre-conditions for both the server environment and the active theme are met, this can lead to remote code execution (RCE).<\/p>\n<h2 class=\"wp-block-heading\">Thank you to these WordPress contributors<\/h2>\n<p class=\"wp-block-paragraph\">This release was led by <a href=\"https:\/\/w.org\/@johnbillion\">John Blackbourn<\/a>. WordPress 7.1.2 would not have been possible without the contributions of the following people:<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/w.org\/@jorbin\">Aaron Jorbin<\/a>, <a href=\"https:\/\/w.org\/@wildworks\">Aki Hamano<\/a>, <a href=\"https:\/\/w.org\/@xknown\">Alex Concha<\/a>, <a href=\"https:\/\/w.org\/@ehti\">Ehtisham Siddiqui<\/a>, <a href=\"https:\/\/w.org\/@fiocavallari\">fiocavallari<\/a>, <a href=\"https:\/\/w.org\/@audrasjb\">Jb Audras<\/a>, <a href=\"https:\/\/w.org\/@jeffpaul\">Jeffrey Paul<\/a>, <a href=\"https:\/\/w.org\/@jeremyfelt\">Jeremy Felt<\/a>, <a href=\"https:\/\/w.org\/@joemcgill\">Joe McGill<\/a>, <a href=\"https:\/\/w.org\/@johnbillion\">John Blackbourn<\/a>, <a href=\"https:\/\/w.org\/@lancewillett\">Lance Willett<\/a>, <a href=\"https:\/\/w.org\/@sirlouen\">Manuel Camargo<\/a>, <a href=\"https:\/\/w.org\/@marcs0h\">marcs0h<\/a>, <a href=\"https:\/\/w.org\/@martinkrcho\">martin.krcho<\/a>, <a href=\"https:\/\/w.org\/@mukesh27\">Mukesh Panchal<\/a>, <a href=\"https:\/\/w.org\/@oglekler\">Olga Gleckler<\/a>, <a href=\"https:\/\/w.org\/@swissspidy\">Pascal Birchler<\/a>, <a href=\"https:\/\/w.org\/@peterwilsoncc\">Peter Wilson<\/a>, <a href=\"https:\/\/w.org\/@rajinsharwar\">Rajin Sharwar<\/a>, <a href=\"https:\/\/w.org\/@ressl\">Ressl<\/a>, <a href=\"https:\/\/w.org\/@shailu25\">Shail Mehta<\/a>, <a href=\"https:\/\/w.org\/@pypwalters\">Stephanie Walters<\/a>, and <a href=\"https:\/\/w.org\/@vortfu\">vortfu<\/a>.<\/p>\n<h2 class=\"wp-block-heading\">CVE and GHSA references<\/h2>\n<p class=\"wp-block-paragraph\">Further details can be found in the advisory: <a href=\"https:\/\/github.com\/WordPress\/wordpress-develop\/security\/advisories\/GHSA-7hp8-65ch-5whp\">CVE-2026-87902 \/ GHSA-7hp8-65ch-5whp<\/a>.<\/p>\n<h2 class=\"wp-block-heading\">Backports<\/h2>\n<p class=\"wp-block-paragraph\">As a courtesy, the security fix is being backported to all branches eligible to receive security fixes (currently through 4.7). As a reminder, <strong>only the most recent version of WordPress is actively supported<\/strong>. The backports are in progress and will ship as they become ready.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This security release features a fix for a critical severity security vulnerability. Because this is a security release, it is recommended that you update your sites immediately. You can download WordPress 7.1.2 from WordPress.org, or visit your WordPress Dashboard, click <a class=\"read-more\" href=\"https:\/\/mailurdu.co.uk\/?p=2747\">\u0645\u0632\u06cc\u062f \u067e\u0691\u06be\u06cc\u06ba<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-2747","post","type-post","status-publish","format-standard","hentry","category-pakistan"],"_links":{"self":[{"href":"https:\/\/mailurdu.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/2747","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mailurdu.co.uk\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mailurdu.co.uk\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mailurdu.co.uk\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mailurdu.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2747"}],"version-history":[{"count":0,"href":"https:\/\/mailurdu.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/2747\/revisions"}],"wp:attachment":[{"href":"https:\/\/mailurdu.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2747"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mailurdu.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2747"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mailurdu.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2747"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}