Critical Security Update: WordPress Core Vulnerability (CVE-2026-87902)

Incident Report for Fasthosts

Resolved

This incident has been resolved.
Posted Sep 24, 2026 - 09:27 BST

Identified

A critical security vulnerability affects WordPress versions 4.7.0 through 7.1.1, which can allow remote code execution under specific conditions.

Managed WordPress Customers
No action needed: Fasthosts is automatically patching your site and deploying proactive security measures

Self-Managed WordPress Customers
Action required: Update WordPress immediately to the latest version

More updates will be posted here as new information becomes available.
Posted Sep 22, 2026 - 22:40 BST
This incident affected: Hosting (WordPress Hosting).