Version 7.1.2

On September 22, 2026, WordPress 7.1.2 was released to the public.

Installation/Update Information

To get this version, update automatically from the Dashboard > Updates menu in your site’s admin area or visit https://wordpress.org/download/releases/.
For step-by-step instructions on installing and updating WordPress:

If you are new to WordPress, we recommend that you begin with the following:

Summary

Security updates

This release features one security fix. Because this is a security release, it is recommended that you update your sites immediately.
The security team would like to thank the following people for responsibly reporting vulnerabilities, and allowing them to be fixed in this release:

  • An unauthenticated path traversal issue in page-template resolution leading to conditional remote code execution reported by Robert Ressl

As a courtesy, these fixes are also available in older affected branches of WordPress. As a reminder, only the most recent version of WordPress is actively supported.

  • WordPress 7.0 is affected by this vulnerability. Version 7.0.6 has been released containing a fix.
  • WordPress 6.9 is affected by this vulnerability. Version 6.9.9 has been released containing a fix.
  • WordPress 6.8 is affected by this vulnerability. Version 6.8.10 has been released containing a fix.
  • WordPress 6.7 is affected by this vulnerability. Version 6.7.9 has been released containing a fix.
  • WordPress 6.6 is affected by this vulnerability. Version 6.6.9 has been released containing a fix.
  • WordPress 6.5 is affected by this vulnerability. Version 6.5.12 has been released containing a fix.
  • WordPress 6.4 is affected by this vulnerability. Version 6.4.12 has been released containing a fix.
  • WordPress 6.3 is affected by this vulnerability. Version 6.3.12 has been released containing a fix.
  • WordPress 6.2 is affected by this vulnerability. Version 6.2.13 has been released containing a fix.
  • WordPress 6.1 is affected by this vulnerability. Version 6.1.14 has been released containing a fix.
  • WordPress 6.0 is affected by this vulnerability. Version 6.0.16 has been released containing a fix.
  • WordPress 5.9 is affected by this vulnerability. Version 5.9.18 has been released containing a fix.
  • WordPress 5.8 is affected by this vulnerability. Version 5.8.17 has been released containing a fix.
  • WordPress 5.7 is affected by this vulnerability. Version 5.7.19 has been released containing a fix.
  • WordPress 5.6 is affected by this vulnerability. Version 5.6.21 has been released containing a fix.
  • WordPress 5.5 is affected by this vulnerability. Version 5.5.22 has been released containing a fix.
  • WordPress 5.4 is affected by this vulnerability. Version 5.4.23 has been released containing a fix.
  • WordPress 5.3 is affected by this vulnerability. Version 5.3.25 has been released containing a fix.
  • WordPress 5.2 is affected by this vulnerability. Version 5.2.28 has been released containing a fix.
  • WordPress 5.1 is affected by this vulnerability. Version 5.1.26 has been released containing a fix.
  • WordPress 5.0 is affected by this vulnerability. Version 5.0.29 has been released containing a fix.
  • WordPress 4.9 is affected by this vulnerability. Version 4.9.33 has been released containing a fix.
  • WordPress 4.8 is affected by this vulnerability. Version 4.8.32 has been released containing a fix.
  • WordPress 4.7 is affected by this vulnerability. Version 4.7.37 has been released containing a fix.
  • WordPress 4.6 and earlier no longer receive security updates.

Change log

List of files revised

/wp-includes/template.php

List of packages revised

No package was revised.

First published

Last updated