Last updated on September 24, 2026 at 02:30 pm

We’re aware of a security vulnerability (CVE-2026-87902) affecting WordPress websites.

If exploited, this vulnerability could allow an attacker to gain control of an affected WordPress site.

The vulnerability affects all WordPress versions before 7.1.2.

What you need to do

If your school website uses WordPress, we recommend checking which version you’re running and ensuring it’s updated to the latest available, secure release.

Website administrators should also ensure that WordPress plugins and themes are kept up to date.

Please refer to this advisory for more information, including on recommended actions.

If you’re unsure whether your school website is impacted, please contact your website administrator or IT contact.