Security Vulnerability in WordPress Core – Update Now!

Also check out below articles

ChatGPT shared conversations are visible to everyone

With the widespread adoption and use of AI in the workplace more and more
Read more

Protect your daily internet use

As a hosting provider we are an integral part of the internet and proud to
Read more

NET 10 now available at MyHostingPartner!

At MijnHostingPartner.de we are constantly working on making our hosting platforms
Read more

Security Vulnerability in WordPress Core – Update Now!

A serious security vulnerability has been discovered in the WordPress core. This allows attackers to take complete control of your website without needing login credentials. Since active attacks may already be underway, it is crucial that you check whether your WordPress website on our hosting server has already been updated.

At MijnHostingPartner.nl, the security of your website and your data is always our top priority. In this article, we’ll briefly explain what this is all about and what you need to do now to protect your website.

What’s going on?

On July 17, 2026, the WordPress security team released an emergency update to patch a dangerous chain of two security vulnerabilities (also known as “wp2shell”).

The vulnerability consists of two components that hackers exploit in combination:

1. CVE-2026-60137 (SQL injection): A vulnerability in WordPress’s database management that allows data to be read or modified.

2. CVE-2026-63030 (Remote Code Execution): An inconsistency in the REST API link’s route.

The major risk: By combining these two vulnerabilities, a hacker can execute malicious code even without an account or active plugins, thereby hijacking your entire website. Since the technical details and pre-built hacking tools (“proof-of-concepts”) are unfortunately already publicly available on the internet, automated bots are currently scanning for vulnerable WordPress sites on a massive scale.

Which versions are vulnerable?

The vulnerability is located in the WordPress core itself. The following versions are at risk and must be updated immediately:

• WordPress 6.8.x (secure as of version 6.8.6)

• WordPress 6.9.x (secure starting with version 6.9.5)

• WordPress 7.0.x (secure starting with version 7.0.2)

What do you need to do?

Step 1: Check your current WordPress version

Although WordPress often performs automatic background updates for such critical security vulnerabilities, these are not enabled on all websites (e.g., due to certain plugin settings or disabled cron jobs). Therefore, do not blindly assume that the update has been applied; instead, check manually.

• Log in to your WordPress dashboard (/wp-admin).

• Go to Dashboard > Updates.

• Check which version is currently active.

Step 2: Manual Update (if necessary)

Do you see that your website is still running on an older version? If so, click the “Update Now” button immediately.

(Tip: To be on the safe side, always create a backup first via our Control Panel, even if the update itself is stable and necessary).

Step 3: Further strengthen security

Do you use a security plugin like Wordfence? If so, make sure this plugin is also fully up to date. Please note: The free version of the Wordfence firewall will not receive specific protection against this attack until 30 days from now (mid-August 2026). Manually or automatically updating your WordPress version is—and remains—the most important defensive measure!

Need help?

Are you having trouble figuring it out on your own, or are you unsure whether your WordPress website at MijnHostingPartner.nl is well protected? Our support team is happy to help. Simply contact us via a ticket in the customer portal or start a chat on our website. We’re happy to help you keep your website secure!

Source: https://www.wordfence.com/blog/2026/07/psa-wordpress-core-patched-unauthenticated-remote-code-execution-vulnerability-chain/