{"id":7408,"date":"2026-09-28T16:04:27","date_gmt":"2026-09-28T16:04:27","guid":{"rendered":"https:\/\/www.hostarmada.com\/blog\/?p=7408"},"modified":"2026-09-28T16:05:19","modified_gmt":"2026-09-28T16:05:19","slug":"wordpress-security-news-september-2026","status":"publish","type":"post","link":"https:\/\/www.hostarmada.com\/blog\/wordpress-security-news-september-2026\/","title":{"rendered":"WordPress Security News September 2026: Key Fixes &amp; Updates"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">September 2026 brought two important WordPress security releases in less than a week. WordPress 7.1.1 addressed 11 security issues on September 17, followed by WordPress 7.1.2 on September 22 with a fix for a critical vulnerability that could, under certain conditions, lead to remote code execution.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If your WordPress website has not been updated yet, we strongly recommend installing the latest available version as soon as possible. WordPress currently recommends updating to 7.1.2, or to the corresponding patched release if you are maintaining an older supported branch.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But if you can&#8217;t update immediately because of compatibility requirements, testing, or other technical constraints, HostArmada customers can consider activating <a href=\"https:\/\/hostarmada.com\/tutorials\/getting-started\/client-area\/armada-v-shield-overview\/\">Armada V-Shield<\/a> for an additional layer of protection. Powered by Patchstack, Armada V-Shield monitors WordPress core, plugins, and themes for known vulnerabilities and can apply mitigation rules for supported vulnerabilities while you prepare to install the official update. It should not be treated as a replacement for keeping WordPress up to date.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s have a look at the WordPress security vulnerabilities addressed during September 2026 and what website owners should do.<\/p>\n\n\n\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_88 ez-toc-wrap-right counter-hierarchy ez-toc-counter ez-toc-transparent ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #565656;color:#565656\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #565656;color:#565656\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/www.hostarmada.com\/blog\/wordpress-security-news-september-2026\/#WordPress_711_Fixed_11_Security_Issues\" >WordPress 7.1.1 Fixed 11 Security Issues<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/www.hostarmada.com\/blog\/wordpress-security-news-september-2026\/#WordPress_712_Fixed_a_Critical_Core_Vulnerability\" >WordPress 7.1.2 Fixed a Critical Core Vulnerability<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/www.hostarmada.com\/blog\/wordpress-security-news-september-2026\/#Which_WordPress_Versions_Should_You_Use\" >Which WordPress Versions Should You Use?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/www.hostarmada.com\/blog\/wordpress-security-news-september-2026\/#What_Should_WordPress_Website_Owners_Do\" >What Should WordPress Website Owners Do?<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/www.hostarmada.com\/blog\/wordpress-security-news-september-2026\/#How_Armada_V-Shield_Can_Help_Protect_WordPress_Websites\" >How Armada V-Shield Can Help Protect WordPress Websites<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/www.hostarmada.com\/blog\/wordpress-security-news-september-2026\/#HostArmadas_Approach_to_WordPress_Security\" >HostArmada&#8217;s Approach to WordPress Security<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/www.hostarmada.com\/blog\/wordpress-security-news-september-2026\/#Keep_Your_WordPress_Website_Protected\" >Keep Your WordPress Website Protected<\/a><\/li><\/ul><\/nav><\/div>\n<h2 id=\"h-wordpress-7-1-1-fixed-11-security-issues\" class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"WordPress_711_Fixed_11_Security_Issues\"><\/span>WordPress 7.1.1 Fixed 11 Security Issues<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">WordPress 7.1.1 was released on September 17, 2026 as both a maintenance and security update.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Alongside fixes for WordPress Core and the Block Editor, the release addressed 11 security issues covering cross-site scripting, access control, path traversal, information disclosure, and other areas of WordPress core.<\/p>\n\n\n\n<h3 id=\"h-unauthenticated-stored-cross-site-scripting-in-wpautop\" class=\"wp-block-heading\">Unauthenticated Stored Cross-Site Scripting in wpautop()<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">One of the more notable vulnerabilities affected <strong>wpautop(),<\/strong> a WordPress function responsible for automatically formatting content.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Under certain circumstances, an unauthenticated visitor could submit content that resulted in stored cross-site scripting (XSS). For comments, successful exploitation was subject to the comment being published, which means normal comment moderation could limit the attack but did not eliminate the vulnerability.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The issue has been assigned <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2026-93485\">CVE-2026-93485<\/a> and received a CVSS 3.1 score of 7.1. It affected WordPress through version 7.1 and was fixed in WordPress 7.1.1. Patchstack also released mitigation protection for this vulnerability.<\/p>\n\n\n\n<h3 id=\"h-other-security-issues-fixed-in-wordpress-7-1-1\" class=\"wp-block-heading\">Other Security Issues Fixed in WordPress 7.1.1<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The release addressed ten additional security issues, including:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>An HTML API issue involving <strong>set_modifiable_text()<\/strong> and HTML comment handling.<\/li>\n\n\n\n<li>Stored cross-site scripting affecting some themes that support custom headers.<\/li>\n\n\n\n<li>Specially crafted URLs that could cause an inactive theme from WordPress.org to be installed and previewed.<\/li>\n\n\n\n<li>A Multisite permissions issue involving network-only plugins.<\/li>\n\n\n\n<li>Authenticated path traversal in the WordPress REST Templates Controller.<\/li>\n\n\n\n<li>An XML-RPC permissions issue involving <strong>customize_changeset<\/strong> posts.<\/li>\n\n\n\n<li>An arbitrary post overwrite vulnerability available to Contributor-level users.<\/li>\n\n\n\n<li>Disclosure of private parent-post titles caused by a missing permission check.<\/li>\n\n\n\n<li>Disclosure of draft and pending post slugs to Contributor-level users.<\/li>\n\n\n\n<li>An authorization issue that allowed authenticated users to reparent comments, including notes.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Several of these vulnerabilities required an authenticated WordPress account or specific user privileges, while others depended on additional user interaction or configuration. Their individual impact therefore varied considerably.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Nevertheless, WordPress recommended that website owners install the security release immediately.<\/p>\n\n\n\n<h2 id=\"h-wordpress-7-1-2-fixed-a-critical-core-vulnerability\" class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"WordPress_712_Fixed_a_Critical_Core_Vulnerability\"><\/span>WordPress 7.1.2 Fixed a Critical Core Vulnerability<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Only five days after WordPress 7.1.1 was released, another security update became necessary.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">WordPress 7.1.2 was released on September 22, 2026 to address a critical vulnerability in WordPress core affecting page template resolution.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The vulnerability is tracked as <a href=\"https:\/\/www.cve.org\/cverecord?id=CVE-2026-87902\">CVE-2026-87902<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An unauthenticated attacker could, under certain conditions, manipulate page template resolution and cause WordPress to include a chosen readable local PHP file located outside the active theme directories.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If additional requirements involving the server environment and active theme were also present, the vulnerability could ultimately lead to remote code execution.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The vulnerability received a <strong>CVSS 4.0 score of 9.2<\/strong> and affected WordPress versions from 4.7 through 7.1.1.<\/p>\n\n\n\n<h3 id=\"h-exploitation-attempts-were-detected-quickly\" class=\"wp-block-heading\">Exploitation Attempts Were Detected Quickly<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The urgency surrounding CVE-2026-87902 increased shortly after the patch became public.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Patchstack reported seeing probing attempts against WordPress websites on September 22, less than five hours after WordPress 7.1.2 was published.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The activity observed at that point consisted of probes rather than successful payload delivery, but it demonstrated how quickly attackers can begin investigating a newly disclosed WordPress vulnerability after a security update becomes available.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Patchstack subsequently released a RapidMitigate rule designed to block exploitation attempts against protected websites.<\/p>\n\n\n\n<h2 id=\"h-which-wordpress-versions-should-you-use\" class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Which_WordPress_Versions_Should_You_Use\"><\/span>Which WordPress Versions Should You Use?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">For websites running the current WordPress branch, the recommended update is <strong>WordPress 7.1.2<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">WordPress also released security backports for older eligible branches. For example, WordPress 7.0.6 was released alongside 7.1.2, with additional patched releases available for older branches. WordPress notes, however, that only the most recent version is actively supported.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Whenever possible, we therefore recommend running the latest stable WordPress release rather than remaining on an older branch solely because a security backport is available.<\/p>\n\n\n\n<h2 id=\"h-what-should-wordpress-website-owners-do\" class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_Should_WordPress_Website_Owners_Do\"><\/span>What Should WordPress Website Owners Do?<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The first step is to check which version of WordPress your website is currently running.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You can do this from your WordPress Dashboard and install available updates from:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Dashboard<\/strong> &gt; <strong>Updates<\/strong> &gt; <strong>Update Now<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Websites configured to receive automatic background security updates may already have received the appropriate patched version. Even so, it is worth checking your website manually to confirm that the update was successfully installed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Before manually updating a production website, make sure you have a recent backup available, particularly if your site uses custom themes, plugins, or functionality that could be affected by a WordPress core update.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you cannot update immediately because you need additional compatibility testing or must resolve another technical dependency first, additional vulnerability protection can help reduce your exposure during that period.<\/p>\n\n\n\n<h2 id=\"h-how-armada-v-shield-can-help-protect-wordpress-websites\" class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_Armada_V-Shield_Can_Help_Protect_WordPress_Websites\"><\/span>How Armada V-Shield Can Help Protect WordPress Websites<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">HostArmada customers can add another security layer with <a href=\"https:\/\/hostarmada.com\/tutorials\/getting-started\/client-area\/armada-v-shield-overview\/\">Armada V-Shield<\/a>, powered by <a href=\"https:\/\/patchstack.com\/articles\/hostarmada-adds-patchstack-to-its-security-stack\/\">Patchstack<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Once activated, Armada V-Shield scans the WordPress environment for known vulnerabilities affecting WordPress core, themes, and plugins. Vulnerabilities can be viewed directly through the <a href=\"https:\/\/hostarmada.com\/tutorials\/getting-started\/client-area\/how-to-access-the-hostarmada-client-area\/\">HostArmada Client Area<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Its protection modules include RapidMitigate WordPress, which can automatically apply mitigation rules for critical vulnerabilities, along with advanced hardening and malicious IP blocking.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That is particularly useful in situations where an official patch exists but cannot be installed immediately. For example, Patchstack released mitigation protection for both the unauthenticated stored XSS addressed by WordPress 7.1.1 and the critical CVE-2026-87902 vulnerability fixed in WordPress 7.1.2.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Virtual protection, however, should complement rather than replace software updates. Once an official WordPress security update is available and has been tested for your website, installing it remains the preferred way to resolve the underlying vulnerability.<\/p>\n\n\n\n<h2 id=\"h-hostarmada-s-approach-to-wordpress-security\" class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"HostArmadas_Approach_to_WordPress_Security\"><\/span>HostArmada&#8217;s Approach to WordPress Security<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">WordPress security should never depend on a single protection mechanism.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">HostArmada combines multiple security layers, including web application firewall protection, network firewall protection, malware scanning and removal, DDoS protection, account isolation, backups, and server-level security measures.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Armada V-Shield extends those protections to the WordPress application itself by detecting known vulnerabilities in WordPress core, plugins, and themes and providing targeted protection against supported threats.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">September&#8217;s WordPress releases demonstrate why this layered approach matters.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">WordPress 7.1.1 addressed 11 security issues, and only five days later WordPress 7.1.2 was required to resolve another critical vulnerability. Website owners may not always have advance notice of when the next vulnerability will be discovered, which makes regular updates, backups, monitoring, and additional security layers an important part of maintaining a WordPress website.<\/p>\n\n\n\n<h2 id=\"h-keep-your-wordpress-website-protected\" class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Keep_Your_WordPress_Website_Protected\"><\/span>Keep Your WordPress Website Protected<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Security vulnerabilities are sometimes discovered even in widely used and actively maintained platforms like WordPress. What matters is how quickly those vulnerabilities are addressed and how quickly website owners install the available fixes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">During September 2026 alone, WordPress released fixes addressing 12 security issues across WordPress 7.1.1 and 7.1.2. Some required authenticated access or specific conditions to exploit, while CVE-2026-87902 posed a much greater risk because an attacker did not need a WordPress account, and remote code execution could be possible when the necessary conditions were present.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The most important action remains straightforward: keep WordPress updated.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Check your WordPress installation and upgrade to WordPress 7.1.2 or the latest available patched version if you have not already done so.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If an immediate update is not practical, HostArmada customers can use Armada V-Shield as an additional layer of protection while preparing and testing the required update.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>September 2026 brought two important WordPress security releases in less than a week. WordPress 7.1.1 addressed 11 security issues on September 17, followed by WordPress 7.1.2 on September 22 with a fix for a critical vulnerability that could, under certain conditions, lead to remote code execution. If your WordPress website has not been updated yet, [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":7413,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[17,36],"tags":[133,1356,769,259,1357,263,1358],"class_list":["post-7408","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","category-wordpress","tag-website-security","tag-wordpress-7-1","tag-wordpress-news","tag-wordpress-security","tag-wordpress-security-updates","tag-wordpress-updates","tag-wordpress-vulnerabilities"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v28.6 (Yoast SEO v28.6) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>WordPress Security News September 2026: Key Fixes &amp; Updates<\/title>\n<meta name=\"description\" content=\"Review the key WordPress security vulnerabilities fixed in September 2026, including WordPress 7.1.1 and the critical 7.1.2 security update.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hostarmada.com\/blog\/wordpress-security-news-september-2026\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"WordPress Security News September 2026: Key Fixes &amp; Updates\" \/>\n<meta property=\"og:description\" content=\"Review the key WordPress security vulnerabilities fixed in September 2026, including WordPress 7.1.1 and the critical 7.1.2 security update.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hostarmada.com\/blog\/wordpress-security-news-september-2026\/\" \/>\n<meta property=\"og:site_name\" content=\"HostArmada Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/HostArmadaINC\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-28T16:04:27+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-28T16:05:19+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hostarmada.com\/blog\/wp-content\/uploads\/2026\/09\/wp-news-september-2026-1.png\" \/>\n\t<meta property=\"og:image:width\" content=\"2400\" \/>\n\t<meta property=\"og:image:height\" content=\"1200\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Emman Zahid\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@HostArmada\" \/>\n<meta name=\"twitter:site\" content=\"@HostArmada\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Emman Zahid\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.hostarmada.com\\\/blog\\\/wordpress-security-news-september-2026\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hostarmada.com\\\/blog\\\/wordpress-security-news-september-2026\\\/\"},\"author\":{\"name\":\"Emman Zahid\",\"@id\":\"https:\\\/\\\/www.hostarmada.com\\\/blog\\\/#\\\/schema\\\/person\\\/49bb87cc02a12993309187df4000dd9e\"},\"headline\":\"WordPress Security News September 2026: Key Fixes &amp; Updates\",\"datePublished\":\"2026-09-28T16:04:27+00:00\",\"dateModified\":\"2026-09-28T16:05:19+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hostarmada.com\\\/blog\\\/wordpress-security-news-september-2026\\\/\"},\"wordCount\":1298,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hostarmada.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hostarmada.com\\\/blog\\\/wordpress-security-news-september-2026\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hostarmada.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/wp-news-september-2026-1.png\",\"keywords\":[\"website security\",\"WordPress 7.1\",\"wordpress news\",\"WordPress security\",\"WordPress Security Updates\",\"WordPress updates\",\"WordPress Vulnerabilities\"],\"articleSection\":[\"News\",\"WordPress\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hostarmada.com\\\/blog\\\/wordpress-security-news-september-2026\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hostarmada.com\\\/blog\\\/wordpress-security-news-september-2026\\\/\",\"url\":\"https:\\\/\\\/www.hostarmada.com\\\/blog\\\/wordpress-security-news-september-2026\\\/\",\"name\":\"WordPress Security News September 2026: Key Fixes &amp; Updates\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hostarmada.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hostarmada.com\\\/blog\\\/wordpress-security-news-september-2026\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hostarmada.com\\\/blog\\\/wordpress-security-news-september-2026\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hostarmada.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/wp-news-september-2026-1.png\",\"datePublished\":\"2026-09-28T16:04:27+00:00\",\"dateModified\":\"2026-09-28T16:05:19+00:00\",\"description\":\"Review the key WordPress security vulnerabilities fixed in September 2026, including WordPress 7.1.1 and the critical 7.1.2 security update.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hostarmada.com\\\/blog\\\/wordpress-security-news-september-2026\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hostarmada.com\\\/blog\\\/wordpress-security-news-september-2026\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hostarmada.com\\\/blog\\\/wordpress-security-news-september-2026\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hostarmada.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/wp-news-september-2026-1.png\",\"contentUrl\":\"https:\\\/\\\/www.hostarmada.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/wp-news-september-2026-1.png\",\"width\":2400,\"height\":1200,\"caption\":\"wp-news-september-2026\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hostarmada.com\\\/blog\\\/wordpress-security-news-september-2026\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"HostArmada Blog\",\"item\":\"https:\\\/\\\/www.hostarmada.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"WordPress Security News September 2026: Key Fixes &amp; Updates\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hostarmada.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.hostarmada.com\\\/blog\\\/\",\"name\":\"HostArmada Blog\",\"description\":\"HostArmada official blog. Useful web hosting related articles.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hostarmada.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hostarmada.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hostarmada.com\\\/blog\\\/#organization\",\"name\":\"HostArmada\",\"url\":\"https:\\\/\\\/www.hostarmada.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hostarmada.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hostarmada.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/Group-7823.png\",\"contentUrl\":\"https:\\\/\\\/www.hostarmada.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/Group-7823.png\",\"width\":240,\"height\":25,\"caption\":\"HostArmada\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hostarmada.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/HostArmadaINC\",\"https:\\\/\\\/x.com\\\/HostArmada\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hostarmada\\\/\"],\"description\":\"HostArmada provides web hosting services for businesses, developers, eCommerce stores, and website owners worldwide. We offer Shared Hosting, WordPress Hosting, VPS Hosting, Cloud Hosting, domain registration, SSL certificates, website migration, and managed server solutions. With high-performance infrastructure, enterprise-grade security, and 24\\\/7 technical support, HostArmada helps customers build fast, secure, and reliable online experiences.\",\"email\":\"company@hostarmada.com\",\"telephone\":\"+1 (302) 549-0737\",\"legalName\":\"HostArmada INC\",\"foundingDate\":\"2019-11-06\",\"numberOfEmployees\":{\"@type\":\"QuantitativeValue\",\"minValue\":\"11\",\"maxValue\":\"50\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hostarmada.com\\\/blog\\\/#\\\/schema\\\/person\\\/49bb87cc02a12993309187df4000dd9e\",\"name\":\"Emman Zahid\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/5e9936c90bf33f64b28ad90e22f2b5f4ad60bf036a7d2849a9655323ba4d7f28?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/5e9936c90bf33f64b28ad90e22f2b5f4ad60bf036a7d2849a9655323ba4d7f28?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/5e9936c90bf33f64b28ad90e22f2b5f4ad60bf036a7d2849a9655323ba4d7f28?s=96&d=mm&r=g\",\"caption\":\"Emman Zahid\"},\"description\":\"Emman is a Content Manager at HostArmada where she helps make complex topics accessible for readers around the world. With 5+ years of experience in crafting SEO content, she\u2019s passionate about making tech topics easy to understand. In her free time, Emman enjoys traveling and watching Formula 1\\\/E races.\",\"sameAs\":[\"https:\\\/\\\/hostarmada.com\"],\"url\":\"https:\\\/\\\/www.hostarmada.com\\\/blog\\\/author\\\/emman-ha\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"WordPress Security News September 2026: Key Fixes &amp; Updates","description":"Review the key WordPress security vulnerabilities fixed in September 2026, including WordPress 7.1.1 and the critical 7.1.2 security update.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hostarmada.com\/blog\/wordpress-security-news-september-2026\/","og_locale":"en_US","og_type":"article","og_title":"WordPress Security News September 2026: Key Fixes &amp; Updates","og_description":"Review the key WordPress security vulnerabilities fixed in September 2026, including WordPress 7.1.1 and the critical 7.1.2 security update.","og_url":"https:\/\/www.hostarmada.com\/blog\/wordpress-security-news-september-2026\/","og_site_name":"HostArmada Blog","article_publisher":"https:\/\/www.facebook.com\/HostArmadaINC","article_published_time":"2026-09-28T16:04:27+00:00","article_modified_time":"2026-09-28T16:05:19+00:00","og_image":[{"width":2400,"height":1200,"url":"https:\/\/www.hostarmada.com\/blog\/wp-content\/uploads\/2026\/09\/wp-news-september-2026-1.png","type":"image\/png"}],"author":"Emman Zahid","twitter_card":"summary_large_image","twitter_creator":"@HostArmada","twitter_site":"@HostArmada","twitter_misc":{"Written by":"Emman Zahid","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.hostarmada.com\/blog\/wordpress-security-news-september-2026\/#article","isPartOf":{"@id":"https:\/\/www.hostarmada.com\/blog\/wordpress-security-news-september-2026\/"},"author":{"name":"Emman Zahid","@id":"https:\/\/www.hostarmada.com\/blog\/#\/schema\/person\/49bb87cc02a12993309187df4000dd9e"},"headline":"WordPress Security News September 2026: Key Fixes &amp; Updates","datePublished":"2026-09-28T16:04:27+00:00","dateModified":"2026-09-28T16:05:19+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hostarmada.com\/blog\/wordpress-security-news-september-2026\/"},"wordCount":1298,"commentCount":0,"publisher":{"@id":"https:\/\/www.hostarmada.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.hostarmada.com\/blog\/wordpress-security-news-september-2026\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hostarmada.com\/blog\/wp-content\/uploads\/2026\/09\/wp-news-september-2026-1.png","keywords":["website security","WordPress 7.1","wordpress news","WordPress security","WordPress Security Updates","WordPress updates","WordPress Vulnerabilities"],"articleSection":["News","WordPress"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hostarmada.com\/blog\/wordpress-security-news-september-2026\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hostarmada.com\/blog\/wordpress-security-news-september-2026\/","url":"https:\/\/www.hostarmada.com\/blog\/wordpress-security-news-september-2026\/","name":"WordPress Security News September 2026: Key Fixes &amp; Updates","isPartOf":{"@id":"https:\/\/www.hostarmada.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hostarmada.com\/blog\/wordpress-security-news-september-2026\/#primaryimage"},"image":{"@id":"https:\/\/www.hostarmada.com\/blog\/wordpress-security-news-september-2026\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hostarmada.com\/blog\/wp-content\/uploads\/2026\/09\/wp-news-september-2026-1.png","datePublished":"2026-09-28T16:04:27+00:00","dateModified":"2026-09-28T16:05:19+00:00","description":"Review the key WordPress security vulnerabilities fixed in September 2026, including WordPress 7.1.1 and the critical 7.1.2 security update.","breadcrumb":{"@id":"https:\/\/www.hostarmada.com\/blog\/wordpress-security-news-september-2026\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hostarmada.com\/blog\/wordpress-security-news-september-2026\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hostarmada.com\/blog\/wordpress-security-news-september-2026\/#primaryimage","url":"https:\/\/www.hostarmada.com\/blog\/wp-content\/uploads\/2026\/09\/wp-news-september-2026-1.png","contentUrl":"https:\/\/www.hostarmada.com\/blog\/wp-content\/uploads\/2026\/09\/wp-news-september-2026-1.png","width":2400,"height":1200,"caption":"wp-news-september-2026"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hostarmada.com\/blog\/wordpress-security-news-september-2026\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"HostArmada Blog","item":"https:\/\/www.hostarmada.com\/blog\/"},{"@type":"ListItem","position":2,"name":"WordPress Security News September 2026: Key Fixes &amp; Updates"}]},{"@type":"WebSite","@id":"https:\/\/www.hostarmada.com\/blog\/#website","url":"https:\/\/www.hostarmada.com\/blog\/","name":"HostArmada Blog","description":"HostArmada official blog. Useful web hosting related articles.","publisher":{"@id":"https:\/\/www.hostarmada.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hostarmada.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hostarmada.com\/blog\/#organization","name":"HostArmada","url":"https:\/\/www.hostarmada.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hostarmada.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.hostarmada.com\/blog\/wp-content\/uploads\/2026\/06\/Group-7823.png","contentUrl":"https:\/\/www.hostarmada.com\/blog\/wp-content\/uploads\/2026\/06\/Group-7823.png","width":240,"height":25,"caption":"HostArmada"},"image":{"@id":"https:\/\/www.hostarmada.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/HostArmadaINC","https:\/\/x.com\/HostArmada","https:\/\/www.linkedin.com\/company\/hostarmada\/"],"description":"HostArmada provides web hosting services for businesses, developers, eCommerce stores, and website owners worldwide. We offer Shared Hosting, WordPress Hosting, VPS Hosting, Cloud Hosting, domain registration, SSL certificates, website migration, and managed server solutions. With high-performance infrastructure, enterprise-grade security, and 24\/7 technical support, HostArmada helps customers build fast, secure, and reliable online experiences.","email":"company@hostarmada.com","telephone":"+1 (302) 549-0737","legalName":"HostArmada INC","foundingDate":"2019-11-06","numberOfEmployees":{"@type":"QuantitativeValue","minValue":"11","maxValue":"50"}},{"@type":"Person","@id":"https:\/\/www.hostarmada.com\/blog\/#\/schema\/person\/49bb87cc02a12993309187df4000dd9e","name":"Emman Zahid","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/5e9936c90bf33f64b28ad90e22f2b5f4ad60bf036a7d2849a9655323ba4d7f28?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/5e9936c90bf33f64b28ad90e22f2b5f4ad60bf036a7d2849a9655323ba4d7f28?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/5e9936c90bf33f64b28ad90e22f2b5f4ad60bf036a7d2849a9655323ba4d7f28?s=96&d=mm&r=g","caption":"Emman Zahid"},"description":"Emman is a Content Manager at HostArmada where she helps make complex topics accessible for readers around the world. With 5+ years of experience in crafting SEO content, she\u2019s passionate about making tech topics easy to understand. In her free time, Emman enjoys traveling and watching Formula 1\/E races.","sameAs":["https:\/\/hostarmada.com"],"url":"https:\/\/www.hostarmada.com\/blog\/author\/emman-ha\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hostarmada.com\/blog\/wp-json\/wp\/v2\/posts\/7408","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hostarmada.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hostarmada.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hostarmada.com\/blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hostarmada.com\/blog\/wp-json\/wp\/v2\/comments?post=7408"}],"version-history":[{"count":2,"href":"https:\/\/www.hostarmada.com\/blog\/wp-json\/wp\/v2\/posts\/7408\/revisions"}],"predecessor-version":[{"id":7411,"href":"https:\/\/www.hostarmada.com\/blog\/wp-json\/wp\/v2\/posts\/7408\/revisions\/7411"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hostarmada.com\/blog\/wp-json\/wp\/v2\/media\/7413"}],"wp:attachment":[{"href":"https:\/\/www.hostarmada.com\/blog\/wp-json\/wp\/v2\/media?parent=7408"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hostarmada.com\/blog\/wp-json\/wp\/v2\/categories?post=7408"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.hostarmada.com\/blog\/wp-json\/wp\/v2\/tags?post=7408"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}