WordPress patched a critical vulnerability (CVE-2026-87902, CVSS 9.2) affecting versions 4.7.0 through 7.1.1 that allows unauthenticated attackers to load external PHP files, potentially enabling code execution on some servers. The fix shipped September 22 across all supported branches, and site owners are urged to update immediately as no workaround exists.