A critical security vulnerability has been discovered in WordPress Core that allows an attacker to execute arbitrary code on a WordPress server without any authentication. The vulnerability requires no plugins or special configuration – a plain default installation is sufficient. Active exploitation of the vulnerability has already been observed.
WordPress released security patches on 17 July 2026. Due to the severity of the vulnerability, WordPress.org has enabled forced automatic updates for affected versions. We nonetheless urge all of our customers to verify that the update has been applied.
Required actions
Even though WordPress has activated forced updates, please confirm that your installation is running one of the patched versions: 7.0.2, 6.9.5, or 6.8.6. We always recommend keeping WordPress updated to the latest available version.
Your WordPress version number is visible in the WordPress admin panel under Dashboard in the left-hand menu, or in Plesk under the WordPress option in the left-hand sidebar. You can also perform the update from either of these locations by following our general update guide (remember to take a backup before updating).
If you have a separate WordPress administrator, arrange the updates with them as needed
Further information and sources
Read more about the vulnerability and fixes from:
Traficom / Finnish Cybersecurity Centre: https://www.kyberturvallisuuskeskus.fi/fi/haavoittuvuudet/haavoittuvuus-2026-18
WordPress 7.0.2 release announcement: https://wordpress.org/news/2026/07/wordpress-7-0-2-release/
wp2shell – original disclosure by the discoverer (Searchlight Cyber): https://wp2shell.com/
Hostaan Ltd
Snellmaninkatu 36-38
FI-70100 KUOPIO, Finland
Customer Service
Tel +358 20 732 0000
Support@hostaan.com
Company VAt CODE
FI29506566
VAT. REG.
We are a Carbon negative company