HostleloBlogExplore hosting

WordPress 7.1.2 security update:a step-by-step checklist

WordPress 7.1.2 fixes a critical severity vulnerability. Check your version, confirm auto-updates, back up, update by dashboard or WP-CLI, verify and test.

A website window protected by a shield while a coral block is replaced with a fresh green block.
On this page

The short answer

WordPress 7.1.2 (22 September 2026) fixes what its release post calls a critical severity vulnerability, and the team recommends updating immediately; the fix was backported to branches through 4.7. Check your version in Dashboard, Updates or with wp core version, confirm automatic updates are not disabled in wp-config.php, take a backup, then update from the dashboard, your hosting panel or WP-CLI. Verify core files with wp core verify-checksums and click through forms and checkout afterwards.

If your WordPress site is not on version 7.1.2 yet, update it today. WordPress 7.1.2, released on 22 September 2026, fixes what its release post calls "a critical severity security vulnerability", and the WordPress team recommends updating immediately. At the time of writing (3 October 2026), it is the current release. The job usually takes a few minutes: check your version, take a backup, update, confirm and click through the site. This checklist walks through each step, including what to do when the update will not install.

What happened in WordPress 7.1.1 and 7.1.2?

Two security releases landed five days apart. Here is what the official posts say.

  • 7.1.1 (17 September 2026) is a maintenance and security release with 17 bug fixes for core, 19 for the block editor, and 11 security fixes.
  • 7.1.2 (22 September 2026) is a security release that "features a fix for a critical severity security vulnerability."

The 7.1.2 post describes the problem like this: an unauthenticated attacker can, under certain conditions, make page template resolution include a chosen readable local PHP file outside the active theme directories. If the pre-conditions for both the server environment and the active theme are met, this can lead to remote code execution.

That wording matters. It does not say every site is exposed, and it does not say whether attacks have been seen; this article makes no claim about that either. What it does say is that the fix was backported to every branch still eligible for security fixes, currently through 4.7, and that you should update immediately. Both posts use the same line: "Because this is a security release, it is recommended that you update your sites immediately." Only the 7.1.2 post uses the word critical.

Think of it like a recall notice for a car part. Not every car will fail, but the fix is free, quick, and much cheaper than finding out the hard way.

Step 1: Check which version you are running

Log in and open Dashboard > Updates. The page shows your current version and whether a newer one is available. The version number also appears at the bottom right of most admin screens.

If you have command line access, WP-CLI tells you in one line:

wp core version

You want to see 7.1.2 or higher. If your site runs an older branch, such as 6.x, the WordPress team says the fix reaches every branch still receiving security fixes, back to 4.7. Look for the minor update that matches your branch if you cannot jump to 7.1 yet, but plan to move to the current version, because only the most recent version is actively supported.

Step 2: Find out whether WordPress updates itself

Often it does. Both release posts say that if your site supports automatic background updates, the update process begins automatically. WordPress's documentation explains the defaults: existing installations receive minor core updates by default, and fresh installs on 5.6 or later get minor and major core updates unless WordPress detects a version control checkout.

But "often" is not "always". Auto-updates can be turned off in wp-config.php, by a plugin, or by a host that manages updates itself, and some updates fail quietly because of file permissions. A made-up example: a small shop owner switched off all updates two years ago after a plugin broke her checkout, and forgot. Her site would still be on 7.1.0 today, and nothing would have told her.

Look in wp-config.php for these lines, which WordPress documents:

define( 'WP_AUTO_UPDATE_CORE', 'minor' ); // minor updates on, major off
define( 'WP_AUTO_UPDATE_CORE', true );    // all core updates on
define( 'WP_AUTO_UPDATE_CORE', false );   // all core updates off
define( 'AUTOMATIC_UPDATER_DISABLED', true ); // every automatic update off

Your file should contain at most one of the first three lines. If you find false or AUTOMATIC_UPDATER_DISABLED, ask whoever set it why before changing anything; there may be a reason, such as a host that updates for you. For most small sites, 'minor' or true is a sensible setting.

Step 3: Take a backup first

Take a full backup of your files and database before you press anything. A security update is small, but a backup turns a bad afternoon into a five-minute restore.

  • Use your host's backup tool, or a backup plugin you already trust.
  • Download one copy somewhere other than the server.
  • Confirm the backup finished and the file size looks sensible.

With WP-CLI, a quick database export looks like this:

wp db export before-7-1-2.sql

If you want a refresher on downloading files and databases from cPanel, our WordPress migration guide shows the same backup steps.

Step 4: Update WordPress

From the dashboard

For most sites: Dashboard > Updates, click Update Now, and wait for the success message without closing the tab.

From your hosting panel

Many panels, including Softaculous, offer a one-click WordPress update next to your installation.

With WP-CLI

Update core, run any database upgrade, and confirm the version:

wp core update
wp core update-db
wp core version

If you want to stay on your current major branch for now, wp core update --minor applies only minor releases.

By hand

Download the release from wordpress.org and replace the core files. WordPress's documentation says not to delete wp-config.php, the wp-content folder, or your .htaccess and robots.txt if you customised them.

While you are there, update plugins and themes that have updates waiting. The 7.1.2 post describes a pre-condition tied to the active theme, so keeping your theme current is sensible housekeeping, not a guaranteed shield. On the Plugins screen, you can also turn on auto-updates for individual plugins you trust.

Step 5: Confirm the core files are genuine

This optional check compares your core files with the official checksums from WordPress.org. It is a good habit after any security release:

wp core verify-checksums

A healthy site reports "Success: WordPress installation verifies against checksums." If it lists modified or unexpected files, compare against a clean download and ask your host or a developer to look more closely before assuming the worst.

What if the update will not install?

First, check whether your host manages core updates for you. Some managed plans update WordPress on their own schedule, and the Updates screen may look locked. A short message to support settles it.

Common causes and fixes:

  • The update fails or hangs: check free disk space and file permissions, then retry. If WP-CLI says another update is in progress and you are sure none is running, WP-CLI's documentation suggests clearing the lock with wp option delete core_updater.lock.
  • Auto-updates are disabled in wp-config.php: see Step 2, and talk to whoever set it.
  • Your host pins an older version: ask when they will move you to 7.1.2, and ask for a date in writing.
  • The site breaks after updating: restore your backup, then update plugins one at a time to find the conflict.

If you cannot update at all, tell your host that the WordPress team has published a critical severity security fix and ask what they can do for your account. Keep it factual and ask for a timeline.

What to check after updating

Confirm the version, then click through the site like a visitor. Five minutes is enough.

  • Dashboard > Updates shows 7.1.2 or higher.
  • The homepage, a blog post and a normal page load.
  • The contact form, search and login work.
  • In a shop, add a product to the cart and reach checkout.
  • The error log shows no new PHP warnings (on cPanel, under Metrics > Errors).
  • If pages look stale, clear your cache. Our LiteSpeed Cache guide covers purging.

Keep the backup for a few days in case something surfaces later.

If you look after several sites

Agencies and freelancers often have a dozen WordPress sites to check. A little order helps:

  • List every site and its version, from each dashboard, your hosting panel's application list, or WP-CLI.
  • Update the most exposed first: shops, membership sites, and sites with many plugins or old themes.
  • Tell clients what you did, in one line, so they know their site was handled.

If several sites live in one hosting account and WP-CLI is available, a short loop shows every version at once. Replace the folder names with your own:

for site in ~/public_html ~/shop.example.com ~/blog.example.com; do echo "$site"; wp --path="$site" core version; done

Habits that make the next security release a non-event

  • Leave minor core updates on. They are almost always security and bug fixes.
  • Keep a recent off-server backup, and test a restore now and then.
  • Delete plugins and themes you do not use. Inactive code can still be vulnerable.
  • Use strong, unique admin passwords and two-step login for administrator accounts.
  • Watch the official news. Security releases are announced on the WordPress.org news blog.

What comes next?

The WordPress roadmap lists version 7.2 as projected for 10 December 2026, and notes that projected dates are for rough planning only. Until then, expect more minor releases like these two.

The one message worth forwarding

If someone else manages your site, send this:

"WordPress 7.1.2 is a security release the WordPress team recommends installing immediately. Please confirm our site is on 7.1.2 or higher, that a backup was taken first, that minor core updates are switched on, and that the site, forms and checkout still work."

The takeaway: check your version today, back up, update, verify, and spend five minutes clicking through the site.

Reader questions

Is WordPress 7.1.2 a critical security update?

The 7.1.2 release post says it features a fix for a critical severity security vulnerability and recommends updating immediately. The 7.1.1 post, five days earlier, does not use the word critical.

Does WordPress 7.1.2 install automatically?

If your site supports automatic background updates, the update can start on its own. Existing sites get minor core updates by default, but a wp-config.php setting, a plugin or your host can turn this off, so check your version.

How do I check my WordPress version?

Open Dashboard, then Updates, or look at the bottom right of an admin screen. With command line access, run wp core version.

How do I update WordPress with WP-CLI?

Run wp core update, then wp core update-db, then wp core version to confirm. Use wp core update --minor if you only want minor releases on your current branch.

My site runs WordPress 6.x. Is it protected?

The WordPress team says the fix was backported to all branches still eligible for security fixes, currently through 4.7. Install the minor update for your branch, and plan to move to the current version, which is the only one actively supported.

What if my host blocks the WordPress update?

Ask whether core updates are managed on their schedule and for a date to reach 7.1.2. Also check disk space, file permissions and any WP_AUTO_UPDATE_CORE or AUTOMATIC_UPDATER_DISABLED line in wp-config.php.

When is WordPress 7.2 due?

At the time of writing, the WordPress roadmap projects 7.2 for 10 December 2026, and notes that projected dates are for rough planning only.

Sources & further reading

  1. WordPress 7.1.2 Security Release
  2. WordPress 7.1.1 Maintenance and Security Release
  3. WordPress: Upgrading WordPress and automatic updates
  4. WP-CLI: wp core update
  5. WP-CLI: wp core verify-checksums
  6. WordPress Roadmap

Originally published . About our editorial updates.

Your next project deserves a better foundation.

Explore hosting built for your next chapter.

Explore hosting