Critical Security Update: WordPress Core Vulnerability (CVE-2026-87902)

Incident Report for ionos.co.uk

Identified

A critical security vulnerability affects WordPress versions 4.7.0 through 7.1.1, which can allow remote code execution under specific conditions.

Managed WordPress Customers
No action needed:IONOS is automatically patching your site and deploying proactive security measures

Self-Managed WordPress Customers
Action required: Update WordPress immediately to the latest version

More updates will be posted here as new information becomes available.
Posted Sep 22, 2026 - 22:36 BST
This incident affects: Hosting (Wordpress Hosting, Wordpress Pro).