Radar Daily Briefings
A clearer signal for WordPress and engineering
/\_/\
(=^.^=)
(")_(")
/\_/\
(=^.^=)
(")_(")
WordPress CVE-2026-87902 draws probing after patch release
Patchstack reports that WordPress CVE-2026-87902 was probed less than five hours after WordPress 7.1.2 was published. The vulnerability is fixed in 7.1.2 and backported releases including 7.0.6, 6.9.9, 6.8.10, and 4.7.37.
The observed requests use double-encoded traversal and require a valid page_id alongside pagename. They point inclusion at ordinary core files such as wp-links-opml.php, producing a signal that can reveal whether a host is vulnerable. Patchstack says these were reconnaissance probes, not payload delivery.
Operators should update and review logs for encoded traversal, page-directory prefixes, paired parameters, and unexpected OPML output. Patchstack had not observed execution-capable inclusion targets at publication.
WordPress 7.1.2 fixes CVE-2026-87902 template-resolution vulnerability
WordPress 7.1.2 is a security release fixing CVE-2026-87902, an unauthenticated local file inclusion vulnerability in page template resolution. The WordPress project recommends updating immediately and says the fix was backported through branch 4.7.
Patchstack reports that an unvalidated pagename-derived template path could include a readable local PHP file outside active theme directories. Under additional server and theme conditions, that inclusion can lead to remote code execution.
The release validates the affected path and adds containment checks requiring resolved templates to remain within allowed theme locations. Operators should upgrade promptly; the RCE outcome is conditional on the documented environment and theme prerequisites.
WordPress patches critical unauthenticated path traversal vulnerability
WordPress has released security updates for a critical unauthenticated path traversal vulnerability, according to Wordfence. The advisory instructs site owners to update WordPress Core immediately.
Wordfence reports that exploitation can lead to local PHP file inclusion. On affected server and theme configurations, the issue can also lead to remote code execution.
Operators should prioritize updating WordPress Core and review whether their deployments use configurations covered by the advisory. The supplied material does not identify affected versions, the fixed release, the technical root cause, or exploit details.
UK AISI adopts EvalEval infrastructure for reproducible benchmarks
The UK AI Security Institute is using EvalEval’s infrastructure to publish evaluation methods, findings, configuration information, and verified results through Evaluation Cards. The release covers five benchmarks and six frontier models, plus two related cyber evaluations.
The shared Every Eval Ever schema organizes benchmark metadata, evaluation-run data, model metadata, and contextual information. The article says this structure supports transcript-level transparency and comparison across different evaluation setups. It also reports that Humanity’s Last Exam performance varies with evaluation protocol and inference-time compute.
The release gives engineers more context for interpreting benchmark claims and examining individual studies. However, the supplied article offers limited implementation detail, and the cyber results use a different, partially overlapping model set.
Transformers adds GGUF support with llama.cpp kernels
Hugging Face documents new GGUF support in Transformers, allowing users to load quantized checkpoints through familiar Python and PyTorch APIs. The initial work targets local inference on Apple Silicon and is available from the latest Transformers main branch.
The integration reuses ggml Metal kernels for quantized matrix operations, normalization, attention, and related model components. Changes to generate reduce unnecessary masking and defer stopping checks to limit CPU–GPU synchronization.
The packed path is MPS-only and currently covers Qwen3.5 and compatible Qwen3.8 architectures. Comparisons with llama.cpp are indicative rather than directly equivalent because the reported measurements use different throughput conditions.
Redis caching case study details clustered batching failures
A production case study describes a route-estimate cache whose initial Redis batching approach failed in a cluster. Keys derived from H3 origin and destination cells landed across many hash slots, so client-side MGET and MSET operations became numerous per-node requests or produced CROSSSLOT errors.
The author uses Redis hash tags to control slot placement, selecting tag integers by walking CRC16 results until configured capacity is distributed across primaries. Keys are grouped by slot before fan-out, and a Lua EVAL script supplies atomic bulk writes with expiry because MSET lacks TTL arguments. Cached JSON values are replaced with compact CSV.
The account is workload-specific and supplies no independent benchmark or comparative evaluation.
Anthropic releases Claude Opus 5.5 amid LLM price competition
Anthropic has released Claude Opus 5.5, the first model in its Claude 5.5 family. Anthropic says it matches Claude Fable 5.1 on most work and costs 40% less to run than Opus 5.
The primary article lists pricing of $4 per million input tokens and $20 per million output tokens, with cache reads reduced from the prior Opus pricing. Simon Willison also reports that maximum reasoning twice exhausted Opus 5.5’s 128,000-token output limit during an SVG-generation test.
The release is relevant to model and cost selection, but the failure evidence is narrow and the broader performance claims rely on company testing and informal observations.
WordPress Campus Connect updates standards for hands-on student outcomes
WordPress Campus Connect has updated its event guidance after reviewing how the series matured. The project says some events began resembling mini WordCamps, with seminars and presentations taking precedence over hands-on student experiences.
Organizers are asked to build events around tangible outcomes. Examples include creating a WordPress.org account, building a first website, or making a contribution. The Event Formats & Standards and Program Content & Delivery handbook pages now clarify this expectation.
Event Supporters will use the guidance when vetting proposals. The document allows organizers whose concepts do not fit these requirements to consider a different WordPress education format, but it provides limited operational detail.
WordPress hosting agenda schedules release and roadmap discussions
The WordPress Hosting Team agenda schedules meetings in the community Slack channel on September 23, 2026, at 0900 UTC and 1800 UTC. It invites additions or suggestions for the discussion.
Listed topics include the WordPress 7.1.2 security release, the roadmap to 7.2, an update on a server-aware hosting approach, a proposed new default theme named Ipsum, and testing for the DataForm editor inspector.
The agenda is useful for contributors tracking coordination topics and participation times, but it records no decisions, implementation details, or meeting outcomes. The supplied evidence therefore does not establish a completed change or release.
WordPress 6.2.13 is tagged in the official repository
The official WordPress wordpress-develop repository contains a 6.2.13 tag, identified by commit 3e52d0f. The page records that johnbillion tagged it on 22 September 2026.
The supplied evidence confirms the version tag and repository location, but it does not describe what changed in the release. No fixes, compatibility notes, migration guidance, or release contents are provided.
Maintainers tracking the WordPress 6.2 branch can use the tag and commit as a reference point. Further assessment requires release notes or the unavailable assets; the page reports an error while loading those assets.