If you manage a WordPress website, don’t put this off. WordPress released emergency security updates on July 17, 2026, addressing vulnerabilities that security researchers have linked to active exploitation of unpatched websites.
Most eligible websites received the update automatically, but automatic updates don’t always succeed. If your website uses custom deployment workflows, version pinning, Git-based deployments, or other non-standard configurations, it’s important to verify that the update was installed successfully.

Your website should be running one of these patched versions:
| WordPress Branch | Secure Version |
|---|---|
| WordPress 7.0 | 7.0.2 |
| WordPress 6.9 | 6.9.5 |
| WordPress 6.8 | 6.8.6 |
If you’re running an older version within one of these branches, update immediately.
Why This Security Update Is Different
Not every WordPress update requires immediate attention.
This one does.
The vulnerabilities addressed in the July 17 emergency release are associated with the exploit chain commonly referred to as wp2shell. Following public disclosure, security researchers observed exploitation attempts against unpatched websites, and the affected vulnerabilities were later added to CISA’s Known Exploited Vulnerabilities (KEV) Catalog.
Unlike many WordPress security issues that depend on a vulnerable plugin or compromised credentials, this exploit chain targets affected WordPress core installations. For impacted versions, an attacker does not need a valid user account or user interaction to begin an attack, making timely patching especially important.
This isn’t a routine feature update—it’s a security update that should be verified as soon as possible.
What Happened?
On July 17, 2026, the WordPress Security Team released emergency updates to address:
- One Critical vulnerability
- One High-Severity vulnerability
The most severe issue carries a CVSS score of 9.8 (Critical), placing it among the highest-risk software vulnerabilities under the Common Vulnerability Scoring System (CVSS).
Because of the severity, WordPress initiated forced security updates for supported installations to help reduce the number of vulnerable websites exposed to attacks.
How Quickly Did Attacks Begin?
Security researchers reported exploitation attempts within hours of the security update being released.
Shortly afterward, the affected vulnerabilities were added to CISA’s Known Exploited Vulnerabilities (KEV) Catalog, a list maintained by the U.S. Cybersecurity and Infrastructure Security Agency for vulnerabilities that are known to be actively exploited.
For website owners, that changes the recommendation from:
“Update during your next maintenance window.”
to
“Verify your website today.”
Which Websites Should Check?
This update is relevant for anyone managing a supported WordPress installation, including:
- Business websites
- WooCommerce stores
- Agency-managed client websites
- Membership websites
- Educational institutions
- Nonprofit organizations
- Blogs and content websites
Even if you expect automatic updates to be enabled, confirming your installed version only takes a few minutes.
Which Versions Are Protected?
The latest security releases are:
- WordPress 7.0.2
- WordPress 6.9.5
- WordPress 6.8.6
You do not need to upgrade to WordPress 7.0.2 if you’re already running 6.9.5 or 6.8.6. Each supported branch received its own security update.
While the underlying vulnerabilities are not identical across every supported branch, every supported release should be updated to its latest security version.
Why Unpatched Websites Are at Risk
If an attacker successfully exploits an affected installation, the impact may include:
- Remote code execution on the server
- Malware injection
- Unauthorized administrator accounts
- Website defacement
- SEO spam pages
- Redirects to malicious websites
- Loss of customer trust
- Potential search engine warnings or blacklisting
Once vulnerabilities become publicly known and exploitation begins, delaying security updates significantly increases the risk of compromise.
Did Your Website Update Automatically?
For most supported websites, yes.
Because of the seriousness of these vulnerabilities, WordPress initiated forced security updates for eligible installations.
However, automatic updates may not succeed if your website uses:
- Git-based deployments
- Version pinning
- Custom deployment pipelines
- Restricted file permissions
- Enterprise deployment workflows
- Hosting environments requiring manual approvals
If your website falls into any of these categories, verify the installed version manually.
How to Check Your WordPress Version
Checking your version takes less than two minutes.
Method 1: Dashboard → Updates
- Log in to your WordPress Admin dashboard.
- Navigate to Dashboard → Updates.
- Confirm your website is running:
- 7.0.2
- 6.9.5
- 6.8.6
If you’re running an earlier version within your branch, update immediately.
Method 2: Site Health
Navigate to:
Tools → Site Health → Info
Expand the WordPress section to view your installed version.
Method 3: Use a Public Version Checker
If you prefer an additional verification method, reputable public tools—such as wp2shell.com, where available—can help determine whether your website has received the latest security update. Always confirm the result against your WordPress dashboard or hosting control panel.
Signs Your Website May Need Immediate Attention
Even if your website appears to be functioning normally, investigate immediately if you notice:
- Unknown administrator accounts
- Unexpected plugins or themes
- Spam pages appearing in Google Search
- Unexplained redirects
- Website defacement
- Browser security warnings
- Unusual server activity
- Unexpected file modifications
These indicators don’t necessarily point to this specific vulnerability, but they warrant an immediate security review.
WordPress Security Best Practices
Emergency patches are only one part of maintaining a secure website.
To improve long-term security:
- Enable automatic security updates where appropriate.
- Keep WordPress core updated.
- Update plugins and themes promptly.
- Remove unused plugins and themes.
- Use strong passwords and multi-factor authentication (MFA).
- Limit administrator privileges.
- Schedule regular automated backups.
- Monitor your website for suspicious activity.
Consistent maintenance significantly reduces the risk of future security incidents.
Frequently Asked Questions
Which WordPress versions include the July 2026 security fixes?
The patched versions are:
- WordPress 7.0.2
- WordPress 6.9.5
- WordPress 6.8.6
Do I need to upgrade to WordPress 7.0.2?
No.
If your website is already running 6.9.5 or 6.8.6, you’re protected by the corresponding security release for your supported branch.
Why is this update considered critical?
The emergency release addresses vulnerabilities that researchers associated with active exploitation. The most severe vulnerability carries a CVSS score of 9.8 (Critical), and the affected vulnerabilities were added to CISA’s Known Exploited Vulnerabilities (KEV) Catalog, indicating they should be remediated as quickly as possible.
Did WordPress force this update?
Yes.
WordPress initiated forced security updates for eligible supported installations. However, websites with custom deployment workflows or other non-standard configurations should still verify that the update completed successfully.
How do I check which WordPress version I’m running?
Log in to your WordPress dashboard and visit Dashboard → Updates or Tools → Site Health → Info to view your installed version.
Official Resources
For the latest information and technical guidance, refer to the official resources from the WordPress project and trusted security organizations:
- WordPress News
- WordPress Security Releases
- WordPress Developer Documentation
- WordPress Automatic Updates Documentation
- CISA Known Exploited Vulnerabilities (KEV) Catalog
Final Thoughts
Many WordPress updates improve performance, fix bugs, or introduce new features. This emergency security release is different.
The vulnerabilities addressed in the July 2026 update have been associated with active exploitation, making prompt verification more important than routine maintenance. Even if you expect your website to have updated automatically, it’s worth confirming that you’re running WordPress 7.0.2, 6.9.5, or 6.8.6, depending on your branch.
A two-minute version check today can help protect your website, your visitors, and your business from a known and actively targeted security risk.