What the WordPress 4.7.0 to 7.1.1 file inclusion bug teaches about patch windows WordPress 7.1.2 was released on 22 September 2026 to fix a remote file inclusion flaw tracked as CVE-2026-87902. The interesting part of this event is not the vulnerability class. It is the timeline. Attack attempts were observed within hours of the patch, and the fix was back-ported to every maintained branch going back to 4.7 [1][2]. According to the project advisory summarized in security reporting, an unaut...