19/07/2026
‼️ Action Required: Critical WordPress vulnerability detected
A critical vulnerability has been disclosed impacting several common WordPress versions. Our systems have detected that you have one or more active WordPress installations running these impacted versions.
This vulnerability can be exploited remotely against a default WordPress installation without requiring additional plugins making it particularly easy to exploit.
The full technical exploit details have not yet been released however additional details are available on CVE-2026-63030 here.
Who does this impact?
This specific vulnerability affects WordPress versions 6.9.0 through 6.9.4 and versions 7.0.0 through 7.0.1. Versions 6.8.0 through 6.8.5 are still vulnerable to SQL injections through a similar path outlined in this exploit.
WordPress Version Affected versions Fixed version
6.8 6.8.0 through 6.8.5 6.8.6
6.9 6.9.0 through 6.9.4 6.9.5
7.0 7.0.0 through 7.0.1 7.0.2
7.1 Beta All beta versions prior to 7.1 Beta 2 7.1 Beta 2
‼️‼️TLDR; Ensure your website is updated to the latest WordPress version - 7.0.2.
My clients: Websites hosted through me have already been updated and websites managed with me are in the process of being updated now. So you don't need to take any further action.
Thanks,
Belinda