Critical WordPress Security Vulnerability: Immediate Update Required!

On July 17, 2026, the WordPress Security Team released critical updates addressing a vulnerability chain that allows unauthenticated attackers to create administrator accounts and execute code. This affects WordPress core versions 6.8 through 7.0.1, making immediate updates essential for site owners.

Key Takeaways

  • Update WordPress to versions 6.8.6, 6.9.5, or 7.0.2 immediately to mitigate risks.
  • The vulnerabilities allow attackers to create admin accounts and execute arbitrary code.
  • Wordfence Premium users received protection on July 17; free users will get it on August 16.

Details of the Vulnerability

The vulnerability chain includes CVE-2026-60137 (an unauthenticated SQL injection) and CVE-2026-63030 (REST API confusion). These vulnerabilities can be exploited together, enabling attackers to gain administrative access and potentially compromise the entire site.

Recommended Actions

Site owners should update to patched versions 6.8.6, 6.9.5, or 7.0.2 immediately. If automatic updates are enabled, most sites should already be secure. For those using Wordfence, Premium users received protection on the day of the vulnerability disclosure, while free users will receive it on August 16, 2026.

Attack Data

Since the vulnerability was disclosed, Wordfence has blocked over 11 million exploit attempts. This highlights the urgency for site owners to ensure their WordPress installations are updated, as attackers are actively exploiting this vulnerability.

Frequently Asked Questions

What versions of WordPress are affected by the vulnerability?

Versions 6.8 through 7.0.1 are affected by the vulnerabilities.

What actions should site owners take to protect their WordPress sites?

Site owners should update to patched versions 6.8.6, 6.9.5, or 7.0.2 immediately.

When will free Wordfence users receive protection against this vulnerability?

Free users will receive protection on August 16, 2026.

What types of vulnerabilities are included in this security issue?

The vulnerabilities include an unauthenticated SQL injection (CVE-2026-60137) and a REST API confusion vulnerability (CVE-2026-63030).

How many exploit attempts have been blocked since the vulnerability disclosure?

Wordfence has blocked over 11 million exploit attempts since the vulnerability was disclosed.