Multiple vulnerabilities were identified in WordPress. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution, sensitive information disclosure and data manipulation on the targeted system. Note: Proof-of-concept code is publicly available for CVE-2026-... Impact Remote Code Execution Information Disclosure Data Manipulation System / Technologies affected WordPress 6.8 WordPress 6.9 WordPress 7.1 Please refer to the link below: https://wordpress.org/news/2026/07/wordpress-7-0-2-release/ Solutions Before installation of the software, please visit the vendor web-site for more details. Apply fixes issued by the vendor: https://wordpress.org/news/2026/07/wordpress-7-0-2-release/
Multiple vulnerabilities in WordPress, including publicly available proof-of-concept code, allow remote attackers to achieve remote code execution, information disclosure, and data manipulation. The article specifically lists WordPress versions 6.8, 6.9, and 7.1 as affected. The vendor-provided solution is to apply the fixes detailed in the WordPress 7.0.2 security release.