What the latest WordPress vulnerabilities mean for your organisation
3 min read.
WordPress issued an emergency security release on 17th July 2026 to fix two vulnerabilities, one rated critical and one high.
Both are now being actively exploited and used together they can allow an attacker to run their own code on the server and take control of the site. WordPress has enabled forced updates for affected versions rather than relying on site owners to apply the patch themselves, which gives an indication of how urgent they considered it.
Affected and fixed versions
It is is unclear how many websites have been affected but the vulnerable versions are from 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1.
The fixes have been implemented in versions 6.9.5 and newer. The vulnerabilities are tracked as CVE-2026-60137 and CVE-2026-63030.
What attackers are doing with the access
Compromising a website is rarely the end goal. Once an attacker controls a site, they can change what visitors see and one method that has become common over the past couple of years is to display a fake verification or error message.
The message tells the visitor to complete a step to continue, usually copying a line of text and running it through Windows Run or PowerShell. Doing so installs malware on that person's machine.
This matters because it changes who is at risk. It is not only an issue for the organisation that owns the website. Anyone visiting the site can be affected, including staff visiting a supplier or partner site that has been compromised without their knowledge.
It also gets past a lot of standard protection. There is no attachment to scan and nothing downloaded that looks suspicious. The site is legitimate and often familiar and the user runs the command themselves.
If your organisation runs a WordPress site
Netprotocol does not maintain client websites, so we cannot check this for our clients. We advise anyone who has a WordPress website to get in contact with whoever manages your site as they should be able to answer the following:
Which version of WordPress the site is currently running
Whether it has been updated to 6.9.5 or newer
Whether automatic updates are enabled
Whether the site has been checked for signs of compromise, as updating does not undo access gained beforehand
Whether plugins and themes are also up to date
What to tell your team
This applies regardless of what your own website runs on, because the risk comes from sites your people visit rather than the one you own.
No legitimate website will ask a user to copy a command, open Windows Run, or paste anything into PowerShell, whether that is to prove they are not a bot or to resolve an error on the page. Anyone who sees a prompt like this should close the page and report it to IT.
If someone has already run a command from a website prompt, the device should be disconnected from the network and checked.