- WordPress Weekly
- WordPress
- Security
- WooCommerce
- SEO
WordPress Weekly: Active Core Exploitation, WooCommerce 11.1.2 and Google’s Spam Update — 28 September 2026
This week's priority is urgent: WordPress 7.1.2 fixes a critical Core vulnerability that is already being actively exploited. WooCommerce stores also have a security-labelled 11.1.2 update to test, while Google's September spam update makes calm measurement more useful than speculative SEO changes.
This briefing was checked on 28 September 2026. Security intelligence, software versions and search rollouts can change quickly, so confirm current vendor guidance before acting. If you missed the previous release cycle, our 21 September WordPress Weekly briefing provides the background to last week's Core and WooCommerce updates.
The practical theme is patch, verify and record. Installing an update matters, but a dependable maintenance process also confirms the version actually changed, checks the customer journeys that matter and investigates credible evidence of exposure.
The week's WordPress updates at a glance
- Act immediately: WordPress 7.1.2 fixes CVE-2026-87902, a critical unauthenticated path-traversal issue that can lead to local file inclusion and, under particular theme and server conditions, remote code execution.
- Assume scanning is widespread: Patchstack reports active exploitation attempts, including efforts to reach
pearcmd.phpand write PHP files. - Update WooCommerce: version 11.1.2 is labelled a security update and also fixes a product-variation gallery regression. It does not require a database update.
- Measure search performance: Google's September 2026 spam update began on 24 September, applies globally and may take up to two weeks to complete.
The Core issue is the clear first priority. Search monitoring should not delay a security update, but the ranking rollout is a good reason to avoid unrelated, sweeping SEO changes that would make later analysis harder.
1. WordPress 7.1.2 is an urgent Core security update
WordPress 7.1.2 was released on 22 September 2026 to fix one critical vulnerability. WordPress explains that an unauthenticated attacker can, under certain conditions, influence page-template resolution so that it includes a readable local PHP file outside the active theme directories. If the necessary theme and server preconditions are present, that path can lead to remote code execution.
The issue is tracked as CVE-2026-87902. WordPress recommends updating immediately. The fix was also backported to eligible older branches, so a site that cannot move straight to 7.1.2 still needs the appropriate patched maintenance release for its branch. The official WordPress version notes list the available backports.
Do not interpret the environmental preconditions as a reason to wait. Assessing every combination of theme templates, PHP configuration and available local files takes longer than applying a supported fix. The proportionate response is to update promptly, then verify the installed version and the site's important functions.
Before changing a business-critical website, confirm that a current backup is usable and identify custom code, integrations or commerce journeys that need focused testing. After updating, clear the appropriate caches and test forms, login, search, scheduled tasks and any route that creates an order or enquiry.
2. Active exploitation changes the response
This is no longer only a disclosure to schedule for a quiet maintenance window. Patchstack reports that probing began within hours of the patch. Its updated analysis describes traffic growing to more than ten times the first evening's volume, public scanning tooling entering circulation and attempts to use pearcmd.php to write attacker-controlled PHP files.
That does not mean every scanned site was compromised. It does mean that a site exposed on an affected version deserves more than a dashboard glance. A sensible review should:
- Confirm the installed WordPress version directly and record the time the patched release was applied.
- Preserve relevant access and security logs before short retention periods or rotation remove useful evidence.
- Look for suspicious requests combining page-template parameters, encoded traversal strings, references to
pearcmdor unusual configuration commands. - Review recently created or modified PHP files, administrator accounts, scheduled tasks and other unexpected changes.
- Escalate credible evidence of successful inclusion, file writing or unauthorised access to an appropriate incident-response process.
Updating closes the known vulnerable path; it does not prove that a site exposed before patching is clean. Equally, a quick automated scan should not be presented as an absolute security guarantee.
Managed hosting can reduce the window of exposure, but verification still matters. WP Engine states that minor security releases are deployed automatically and cannot be deferred. Its process includes testing, yet site owners should still confirm the version shown for each environment and test business-specific behaviour that a simple availability check may not cover.
3. WooCommerce 11.1.2 needs a focused store test
WooCommerce 11.1.2 was also released on 22 September. WooCommerce labels it a security update and says no database update is required. The release tightens validation around email-based product reviews and fixes an infinite-recursion regression that could affect variation-gallery rendering when a theme requests available variations from a template.
Those changes warrant a prompt but focused update. The review fix is relevant to stores that accept public product feedback, while the gallery correction affects a highly visible part of variable-product pages. Testing should cover:
- product reviews and the normal moderation route;
- review-notification emails;
- variable products and their image galleries;
- guest and logged-in checkout;
- customer accounts and transactional emails; and
- payment, fulfilment or stock integrations that depend on WooCommerce.
A release containing only two visible fixes can still deserve careful testing. The useful question is not how long the changelog looks, but whether the changed behaviour sits on a public or revenue-generating journey.
4. Google's September spam update: measure before reacting
The Google Search Status Dashboard records a September 2026 spam update beginning on 24 September at 09:15 PDT. Google says it applies globally and to all languages, and that rollout may take up to two weeks.
Rankings and impressions can move while a broad update rolls out. Record a baseline for Search Console clicks, impressions, average positions and enquiries, then annotate the rollout date. Avoid changing large numbers of titles, service pages and internal links purely in response to a few volatile days; doing so removes the clean comparison needed to understand what changed.
This is still a useful moment for a quality review. Check that local and service pages provide genuinely distinct information, real examples, relevant proof and a clear next step. Remove accidental duplication, doorway-style pages and content that exists only to repeat a place name. Also check Search Console's security and manual-action reports and look for injected pages, because compromised WordPress sites can create both a security problem and a search-quality problem.
Necessary maintenance, accessibility fixes and the urgent Core patch should continue. “Wait for the update to finish” is guidance against speculative SEO churn, not a reason to leave a known vulnerability open.
A practical WordPress checklist for this week
- Inventory: list each site's WordPress, WooCommerce, theme and plugin versions rather than relying on update emails.
- Protect the rollback route: confirm that files and the database are backed up and that someone understands how restoration works.
- Patch Core: install WordPress 7.1.2 or the correct patched backport, then verify the resulting version.
- Review exposure: preserve and inspect relevant logs for sites that were publicly reachable before patching.
- Update WooCommerce: install 11.1.2 and test reviews, variation galleries, checkout, accounts and email delivery.
- Test outcomes: check forms, login, search, scheduled jobs, integrations and other business-critical journeys.
- Record search baselines: note 24 September in analytics and compare settled periods rather than isolated daily movement.
- Document the result: record what changed, who checked it, any evidence found and the remaining follow-up.
If there is evidence of compromise, preserve it and get appropriate help before deleting files or rotating everything at random. Containment, investigation and recovery need to be coordinated so that the evidence and the route back to a trustworthy state are not lost.
The wider trend: maintenance needs evidence
This week's stories reinforce the difference between installing updates and managing a website. A dependable process knows which sites are in scope, acts quickly when the risk justifies it, tests the journeys a customer actually uses and leaves a useful record for the next person.
That is particularly important for agencies and organisations responsible for several WordPress installations. A short, repeatable runbook is more reliable than remembering which dashboard looked green. It also makes responsibilities clearer: who approves an update, who checks the store or form, who reviews the logs and who tells stakeholders what happened.
Security work should remain proportionate. Not every alert proves compromise, and no tool can promise absolute safety. The goal is to reduce exposure, look for credible evidence and make the next decision from facts rather than reassurance alone.
What we will watch next
We will watch for further WordPress guidance on CVE-2026-87902, changes in observed exploitation, follow-up WooCommerce releases and Google's confirmation that the September spam update has completed.
Once the search rollout is complete, compare like-for-like periods and separate sitewide movement from page-specific changes. For WordPress estates, keep checking that automatic updates actually reached every production and staging environment and that any exposed sites have completed the appropriate review.
Need help patching or checking a WordPress site?
Web Wonderland provides WordPress maintenance and support in Essex for organisations that need reliable updates, testing and ongoing technical oversight. For a defined fault or urgent patch-and-review task, our WordPress Fix Desk provides a clear fixed-scope route.
We also provide white-label WordPress development for agencies that need discreet overflow support. Do not send passwords, private keys or access credentials through an enquiry form. Start with the public website URL, the version or warning involved, what you have observed and the business impact; secure access can be arranged after the scope is understood.
Sources and publication note
- WordPress 7.1.2 release announcement
- WordPress 7.1.2 version notes and patched backports
- Patchstack: active exploitation of CVE-2026-87902
- WP Engine: WordPress Core update policy
- WooCommerce 11.1.2 release notes
- Google Search Status Dashboard: September 2026 spam update
This article provides general technical information and is not a guarantee that a website is secure or a substitute for incident-response advice. Check current vendor guidance and the details of your own software and hosting environment before acting.

