Critical Security Update: WordPress Core Vulnerability (CVE-2026-87902)

Incident Report for ionos.co.uk

Resolved

The issue has been resolved.
Posted Sep 25, 2026 - 08:56 BST

Identified

A critical security vulnerability affects WordPress versions 4.7.0 through 7.1.1, which can allow remote code execution under specific conditions.

Managed WordPress Customers
No action needed:IONOS is automatically patching your site and deploying proactive security measures

Self-Managed WordPress Customers
Action required: Update WordPress immediately to the latest version

More updates will be posted here as new information becomes available.
Posted Sep 22, 2026 - 22:36 BST
This incident affected: Hosting (Wordpress Hosting, Wordpress Pro).