Critical WordPress and Next.js Security Updates: Is Your Website Patched?

On 22 September critical security fixes were released for both WordPress and Next.js. Here is a short overview of what they fix and how to check whether your website or online store is protected.

Critical WordPress and Next.js Security Updates: Is Your Website Patched?
In shortOn 22 September 2026, WordPress 7.1.2 was released to fix a critical security vulnerability, and Next.js 16.3.6 was released to fix a critical remote code execution flaw. If your website runs on WordPress or Next.js, make sure these updates are installed.

Security updates are the most important part of website maintenance. Most hacks are not targeted attacks but automated scripts that scan the internet for sites where a known vulnerability has not been patched. The more critical the flaw, the faster attackers exploit it.

Information as of 1 October 2026. For full details, see the official WordPress and Next.js announcements.

WordPress 7.1.2: a critical flaw in page templates

WordPress 7.1.2 was released on 22 September 2026 as a security release. The fixed flaw allowed an unauthenticated attacker to abuse page template resolution to include another PHP file on the server outside the active theme’s directories. Under certain server and theme configurations this could even lead to remote code execution, meaning an attacker could run their own code on the server.

The vulnerability is tracked as CVE-2026-87902. WordPress backported the fix to older branches down to version 4.7, but only the latest version is actively supported.

How to check

  • In the WordPress admin, open Dashboard → Updates and check the installed version. It should be 7.1.2 or newer.
  • WordPress usually installs minor security releases automatically. If automatic updates have been disabled (hosts or developers sometimes do this), the update must be installed manually.
  • Update your plugins and theme at the same time – a large share of WordPress vulnerabilities are actually in plugins.

Next.js: two security updates in a row

22 September: a critical flaw in the image generator

Next.js published an out-of-band update, 16.3.6 (and 15.5.26). The flaw was in the Node.js implementation of ImageResponse (next/og), which is used, for example, to generate social sharing images automatically. Because of improper escaping in an upstream library (Satori), it could lead to remote code execution under specific conditions.

  • Versions 16.2.0 to 16.3.5 are affected.
  • The Edge implementation of ImageResponse is not affected.
  • Version 15.5.26 adds related hardening, but 15.x versions were not affected by the remote code execution flaw.

30 September: a scheduled security release

Next.js announced a scheduled security release with versions 16.3.8 and 15.5.27, fixing seven vulnerabilities (one high, five medium and one low severity). Fixes for two more issues (one critical, one high) are pending upstream coordination and will follow in a later release, so it is worth keeping an eye on Next.js announcements over the coming weeks.

How to check

  • Check your project’s package.json or run npm ls next to see which Next.js version you use.
  • Upgrade to the latest patched version and redeploy – updating the code alone is not enough if the running application on the server stays on the old version.
  • If you use the next/og image generator, check whether it runs in the Node.js or Edge runtime.

A checklist for website owners

  1. Do you know which platform your website or online store runs on and who is responsible for it?
  2. Are WordPress, your plugins and your theme on the latest version?
  3. Do you have a recent backup stored outside the server?
  4. Have unused plugins and themes been removed?
  5. Is someone monitoring security advisories and installing critical updates within days, not months?

Why regular maintenance pays off

A hacked website usually means more than repair work: Google may flag the site as dangerous, your emails may start landing in spam, and if customer data leaks, you are required to notify the data protection authority. Preventive maintenance – updates, backups and security monitoring – costs a fraction of dealing with the consequences.

Summary

The September updates are a good reminder that a website needs care after launch too. If you are not sure whether your site is up to date, get in touch and we will check it. For a long-term solution, see our website maintenance service, where critical updates are installed quickly and tested first.

Frequently asked questions

Does WordPress update itself?

WordPress usually installs minor security releases automatically unless this has been disabled. Plugin and theme updates often need to be enabled separately or installed manually.

How do I know whether my website uses Next.js?

The easiest way is to ask your developer. Technically, traces of Next.js can also be seen in the page source, for example in file paths starting with /_next/.

What should I do if my website has already been hacked?

If necessary, take the site offline temporarily, restore a clean backup, change all passwords and install the updates. If personal data was leaked, the data protection authority must be notified within 72 hours.

Veebiekspert team

We build websites, online stores and business software – and write about what we have actually built.

Learn more: Website maintenance

Tell us what you want to achieve – we will reply within 3 business days with a concrete solution, price and timeline.

View service →

Read next