Web Wiz - Green Windows Web Hosting - Celebrating 25 Years!


WordPress Security Alert - Please Update Your WordPress Sites

11 September 2026

We have started receiving notifications from the UK National Cyber Security Centre (NCSC) about WordPress websites on our network running versions affected by a serious security vulnerability. If you run a WordPress website with us, please check it is up to date as soon as possible.

What is the Issue?
In July 2026 two vulnerabilities were found in WordPress itself: CVE-2026-60137 (SQL injection) and CVE-2026-63030. Used together, an attacker can read your website database, create their own administrator account and take full control of your site, without needing to log in. These vulnerabilities have been actively exploited since July, and attackers are scanning the internet for sites that have not yet been updated.

Affected versions:
WordPress 6.8.0 to 6.8.5
WordPress 6.9.0 to 6.9.4
WordPress 7.0.0 to 7.0.1

These are fixed in WordPress 6.8.6, 6.9.5 and 7.0.2 (or any later version).

If your site is running a version older than 6.8, it is not affected by this particular issue, but older versions will be missing other important security fixes, so we would still recommend updating to the latest version. If your site is several versions behind, it is a good idea to take a backup of your files and database before updating, as older themes and plugins may need updating at the same time.

What You Need to Do
1. Log in to your WordPress admin area.
2. Go to Dashboard > Updates and click "Update Now".
3. While you are there, update any plugins and themes that have updates waiting.

WordPress normally installs security updates automatically, but this does not always happen, for example if automatic updates have been turned off by a plugin or setting. If your site has not updated itself, please update it manually.

Check Your Site
If your site was not updated before the end of July, it is worth taking a few minutes to check nothing has been changed. Updating WordPress fixes the vulnerability, but it will not remove anything that may already have been added to your site.

1. Go to Users and check there are no administrator accounts you do not recognise.
2. Go to Plugins and check there are no plugins you did not install.
3. Check your website pages look as expected and do not redirect visitors elsewhere.
4. Change your WordPress administrator passwords.

If anything looks wrong, please open a support ticket and let us know.

Old or Unused WordPress Sites
If you have an old, test or forgotten WordPress install that you no longer use, please delete it, including its database. Forgotten installs that never get updated are one of the most common ways websites are compromised.

Need Help?
WordPress have a simple step by step guide to updating here: https://wordpress.org/documentation/article/updating-wordpress/





Become a Fan on Facebook Follow us on X Connect with us on LinkedIn Web Wiz Blogs
About Web Wiz | Contact Web Wiz | Terms & Conditions | Cookies | Privacy Notice

Web Wiz® is the trading name of Web Wiz Ltd. Company registration No. 05977755. Registered in England and Wales.
Registered office: Web Wiz Ltd, Unit 18, The Glenmore Centre, Fancy Road, Poole, Dorset, BH12 4FB, UK.

Prices exclude VAT at 20% unless otherwise stated. VAT No. GB988999105 - $, €, prices shown as a guideline only.

Copyright ©2001-2026 Web Wiz® Ltd. All rights reserved.