20/07/2026
A critical security vulnerability has been identified and already patched in WordPress core.
The vulnerability lets an attacker gain administrative access to a site without needing to log in. Cybersecurity researcher Oliver Sild, CEO of Patchstack, has confirmed that this issue is currently being actively exploited in the wild.
Due to the severity, the WordPress.org team has enforced updates with the auto-update system for sites running the affected version. Please check on sites where auto-updates are disabled.
We recommend taking two immediate steps to secure those sites.
To start, verify your exact WordPress version before updating, rather than assuming the most recent release is correct. Depending on your current branch, apply the specific patch: 6.8.6, 6.9.5, or 7.0.2.
Second, review your WordPress user list. Look closely for any administrator accounts that you do not recognise. If you find any unauthorized users, please treat this as a security incident.
If you manage your own updates, please apply this patch as soon as possible. In case you need assistance with updating safely or conducting a security audit, our experts are available to support you.
Did you know that Codeable offers WordPress Maintenance Plans on a monthly retainer basis?
See Maintenance Plans for WordPress: https://www.codeable.io/packages/wordpress-maintenance/
Monthly WordPress maintenance plans from vetted experts. Get safe updates, backups, security monitoring, development time and clear reporting.