WordPress 7.1.2: What to Check After CVE-2026-87902
WordPress 7.1.2 fixes CVE-2026-87902, but patching alone does not prove your site was untouched. Learn what to verify after the update.
Stage | Question to answer | Useful evidence |
Vulnerable | Was this installation on an affected release? | Version and official advisory |
Exposed | Were the relevant theme and server conditions present, and for how long? | Theme layout, server configuration, update records |
Probed or attacked | Did suspicious requests reach this site? | Historical web, WAF and security logs |
Patched | Did the appropriate fixed release install successfully? | Version, update logs and functional checks |
Verified | What changed, what remains, and how is the site behaving now? | File and content review, scan findings, browser checks, reputation and monitoring history |