WordPress sites: two updates to install the week of September 21, 2026
If your site runs on WordPress, two updates cannot wait: WordPress 7.1.2, released on September 22, 2026, and Elementor 4.3.2, released on September 25. Both fix flaws that can hand control of the site to a stranger.
WordPress 7.1.2: a critical flaw that needs no login
CVE-2026-87902 affects every version from 4.7.0 to 7.1.1, and WordPress rates it critical. It requires no account: under certain conditions (a theme containing a folder whose name starts with "page-" and a specific PHP configuration), an attacker can run their own code on the server.
Attacks started right away. Patchstack recorded a first attempt on the day of the release, at 11:49 UTC. By the next day, the volume had grown more than tenfold.
Elementor 4.3.2: a single link is enough
Elementor versions 4.3.0 and 4.3.1, installed on more than two million sites, switch off a WordPress protection against forged requests (CSRF, for cross-site request forgery). A logged-in administrator who clicks a booby-trapped link, received by email or in a comment, can let the attacker create a new administrator account. Patchstack rates the flaw 8.8 out of 10.
What to check this week
- In the dashboard, the Updates page should show WordPress 7.1.2. A site kept on an older branch should be on 7.0.6, 6.9.9 or 6.8.10.
- Under Plugins, Elementor should show 4.3.2 or higher. WordPress security fixes install themselves on most sites, but plugins only do so if their automatic updates are turned on.
- Review the user list. An administrator nobody recognizes gets deleted, and passwords get changed.
Our website maintenance service handles all of this proactively. We apply WordPress, plugin and PHP updates as soon as they are reliable, then check that your site still works. Security (firewall, two-factor authentication, continuous monitoring) stays in place at all times, so you no longer have to follow these announcements yourself.
Who should apply these patches, and how fast, is covered in who applies your site's security patches.
- WordPress.org, WordPress 7.1.2 Release, September 22, 2026. Source for the flaw, the affected versions and automatic updates.
- Patchstack, CVE-2026-87902: Attackers Started Probing WordPress Sites Hours After the Patch, September 2026. Source for the exploitation conditions, the fixed versions and the attack timeline.
- Help Net Security, WordPress 7.1.2 fixes critical unauthenticated path traversal vulnerability, September 23, 2026.
- Patchstack, Cross-Site Request Forgery in Elementor Plugin Affecting 2 Million+ Sites, September 25, 2026. Source for the 8.8 score, the affected versions and the booby-trapped link scenario.

Geneviève puts the strategy for your engagement into action. She leads all our web development projects: Shopify, WordPress and the new ways of building a site with AI. She manages our team of developers and translates your business needs into technical language. She runs your organic search (SEO), your visibility in AI answers (GEO) and your site's conversion rate optimization (CRO). Her work is at the heart of three goals: Attract customers with SEO and AI, Improve your site's conversion, and Strengthen your visibility in AI answers. With Gabriel, she also builds the landing pages for your advertising campaigns. She writes mainly about SEO, AI visibility and web design.
About Falia →