Your website took a booking last Tuesday. On that same Tuesday, a critical patch shipped for the software underneath roughly two in five websites on the internet. Here is the uncomfortable question: do you know whether it reached yours?
Most owners I ask cannot answer. Not because they are careless — because nobody ever gave them the means to answer. That gap is the subject of this piece. The patch itself is almost a footnote.
What shipped on 22 September
The WordPress project released version 7.1.2, fixing CVE-2026-87902. WordPress’s own advisory rates it 9.2 out of 10 — Critical.
The flaw, in the advisory’s exact words: an unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable local .php file outside the active theme directories, and if pre-conditions for both the server environment and the active theme are met, this can lead to RCE.
Plainly: under the right conditions, somebody with no account and no password could get a site to run code it was never meant to run.
- CVSS 4.0 base score
- 9.2 · Critical
- Weakness class
- CWE-98
- Affected versions
- 4.7.0 – 7.1.1
- Patched releases shipped
- 25
- Oldest branch patched
- 4.7.37
- WordPress share of all websites
- 40.2%
- Share of sites with a known CMS
- 58.7%
Advisory GHSA-7hp8-65ch-5whp, published 22 September 2026, read at source. The count of 25 patched releases is ours, counted from the advisory’s own list from 7.1.2 down to 4.7.37 — WordPress does not publish a total. Usage shares: W3Techs, data of 28 September 2026.
WordPress is not the weak link
It would be easy to turn this into a post about WordPress being unsafe. That post would be wrong, and any technical reader would know it within a paragraph.
Look at what actually happened. The flaw was found, fixed and shipped on the same day. The fix was carried back through every branch still eligible for security updates — as far back as 4.7, a line that first shipped years ago. That is 25 separate releases cut so that nobody running an old site would be left without a patch. Minor security updates are enabled by default, and the project’s own administration handbook strongly discourages turning them off. Sites configured for automatic background updates began updating themselves.
Open-source software with a security process that responsive is not the problem here. If anything, the backport effort is the most impressive part of the story and the part nobody will write about.
So what is the weak link?
It is a question, and it is about paperwork rather than code.
Say you run a braiding studio, a barbershop, a catering business. Your website takes bookings. Somebody built it for you, maybe two years ago. Last Tuesday a critical patch shipped for the platform underneath it.
Did it reach your site?
Follow that question honestly and it turns into four. They are not technical questions. Every one is answerable in about a minute, by you, without help:
- Can you log into your own hosting right now? Not email someone who can. You, with credentials you hold.
- Whose name is the domain registered in? Yours, or the agency’s?
- Who has a copy of the source code? If your developer stopped answering tomorrow, what do you actually have?
- Who applied the last security update, and when? Is there anyone whose job that is?
If you cannot answer those four, you do not own a website. You rent one. And renting is perfectly fine right up to the moment something needs fixing — at which point you are waiting on whoever holds the keys, on their schedule, at their price.
This next part is reasoning, not reporting
I want to mark the join, because this is where writing about a security release usually stops being about the security release and starts being a sales pitch wearing its clothes.
Nothing in the advisory says anything about who should own your domain. It is a patch note. What it establishes is narrower: software underneath a large share of the web needs occasional urgent attention, and that attention has to come from a named person.
The step from there to “so you should hold your own logins” is ordinary logic rather than a finding, and you can check it yourself. A patch reaches your site because something automatic applied it, or because a person did. If it was automatic, fine — until the release that needs a human. If it was a person, you had better know which person, and be able to reach them, and be able to get in yourself if you cannot.
None of that requires you to become technical. It requires the accounts to be in your name. It rhymes with something I wrote about earlier this month: whether an AI can recommend a business that actually exists comes down to whether there is a real page anywhere to retrieve — and the same question applies to who that page belongs to.
What ownership actually means, including what it costs
What I build is a complete business website where the domain, the hosting, the source code and every connected account are registered in your name. Not mine. Online booking that takes a deposit up front, an owner’s dashboard so you can see what is happening without asking anyone, built mobile-first because that is where your customers are. Fixed scope, no monthly website subscription.
Now the limits of that promise, because overselling it would be the same mistake as overselling the WordPress story.
Owning your website does not make it free to run. A domain costs money every year. Hosting costs money every month. Stripe takes its percentage of every payment. Anything doing AI work has usage costs. Nobody can build you a system with no running costs, and anyone telling you otherwise is selling you something.
What changes is whose name is on it. Those are your accounts, on your card, visible to you whenever you want to look. The scope is agreed before we start, so the cost is predictable rather than open-ended. And when a patch like last Tuesday’s lands, there is one named person responsible for it — and nobody else holding your logins.
One running live
muriellehairbraids.com is a braiding business taking real bookings and real deposits on a site she owns outright — domain, hosting, code and accounts all in her name. Open it on your phone and go as far as the deposit screen.
That is the whole difference. Not that her site is invulnerable; no site is, and I would not claim it. But when something needs patching there is one person to call, and if she ever wants to, she can get into every account herself.
The takeaway
Security patches are not the interesting part of running a small business, and they never will be. You should not have to think about them.
But you should be able to find out. And it turns out that “can I find out?” is the same question as “do I own this?” — asked in a way you can actually answer on a Tuesday afternoon.
Common questions
How do I know if my website has had its security updates?
Four questions answer it, and none are technical. Can you log into your own hosting right now, with credentials you hold? Whose name is the domain registered in? Who has a copy of the source code? And who applied the last security update, and when? If you cannot answer those, the honest position is that you do not know — and finding out means asking whoever holds the keys.
What is CVE-2026-87902 and how serious is it?
It is a flaw in WordPress patched on 22 September 2026, rated 9.2 out of 10 — Critical — in the project’s own advisory, classed as CWE-98. In the advisory’s words, an unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable local .php file outside the active theme directories, and if pre-conditions for both the server environment and the active theme are met, this can lead to RCE. Versions 4.7.0 through 7.1.1 were affected.
Does this mean WordPress is unsafe?
No, and the evidence points the other way. The flaw was found, fixed and shipped the same day, and the fix was carried back through every branch still eligible for security updates — 25 separate releases, as far back as 4.7. Minor security updates are on by default and the project strongly discourages disabling them. A security process that responsive is not the weak link.
Who is responsible for applying security updates to my business website?
Somebody has to be, and on a lot of small-business sites nobody is. Automatic background updates cover routine minor releases, which handles most cases until a release needs a human. The question worth settling before you need the answer is which named person does it, whether you can reach them, and whether you can get into the accounts yourself if you cannot.
Do I own my website if an agency or a subscription platform built it?
Often not in full. Ownership means the domain, the hosting account, the source code and every connected account — payments, email, analytics — are registered in your name and can be moved, handed to another developer, or sold with the business. On most subscription platforms you are licensing a site that stops working when you stop paying, and the code is not portable. Owning it does not make it free to run: the domain, hosting and payment processing all still cost money. What changes is whose name is on the accounts.
Sources
- WordPress security advisory GHSA-7hp8-65ch-5whp — CVE-2026-87902Published 22 September 2026 · publisher’s own advisory · CVSS 4.0 base score 9.2 Critical, CWE-98, affected 4.7.0–7.1.1 · the severity, the classification and the quoted description were all read in the advisory itself · the count of 25 patched releases is ours, counted from the advisory’s own list from 7.1.2 down to 4.7.37, as no total is published
- WordPress 7.1.2 Release — WordPress.org newsPublished 22 September 2026 · publisher’s own release announcement
- W3Techs — Usage statistics and market share of WordPressData of 28 September 2026 · daily survey · 40.2% of all websites, 58.7% of sites whose content management system is known
- Upgrading WordPress — WordPress Advanced Administration HandbookPublisher’s own documentation · read 28 September 2026 · minor security updates enabled by default, disabling them strongly discouraged
More from the journal
- An AI will recommend a business that does not exist, and sound certainTwo researchers checked every name three AI models recommended against the official register. 4% of the doctors were real — and the invented ones were not random.
- Google is answering your customers without sending them to you68% of US searches now end without a click, and an AI summary halves the rest. What that means if you sell appointments — and why Google says there is no “AI SEO” to buy.
- Your customers are visiting less and spending moreTransactions down 1.8%, average ticket up 3.0%, and services hit hardest of all. What the August 2026 Fiserv data means if you sell appointments.
Sedjro Tovihouande is the founder of Sedjro Digital LLC, where he builds booking, e-commerce and automation systems for service businesses. He is pursuing an M.S. in Information Technology — AWS Cloud Technologies at Purdue Global. Live builds include muriellehairbraids.com.