WordPress Security Alert - Please Update Your WordPress Sites11 September 2026We have started receiving notifications from the UK National Cyber Security Centre (NCSC) about WordPress websites on our network running versions affected by a serious security vulnerability. If you run a WordPress website with us, please check it is up to date as soon as possible. What is the Issue? In July 2026 two vulnerabilities were found in WordPress itself: CVE-2026-60137 (SQL injection) and CVE-2026-63030. Used together, an attacker can read your website database, create their own administrator account and take full control of your site, without needing to log in. These vulnerabilities have been actively exploited since July, and attackers are scanning the internet for sites that have not yet been updated. Affected versions: WordPress 6.8.0 to 6.8.5 WordPress 6.9.0 to 6.9.4 WordPress 7.0.0 to 7.0.1 These are fixed in WordPress 6.8.6, 6.9.5 and 7.0.2 (or any later version). If your site is running a version older than 6.8, it is not affected by this particular issue, but older versions will be missing other important security fixes, so we would still recommend updating to the latest version. If your site is several versions behind, it is a good idea to take a backup of your files and database before updating, as older themes and plugins may need updating at the same time. What You Need to Do 1. Log in to your WordPress admin area. 2. Go to Dashboard > Updates and click "Update Now". 3. While you are there, update any plugins and themes that have updates waiting. WordPress normally installs security updates automatically, but this does not always happen, for example if automatic updates have been turned off by a plugin or setting. If your site has not updated itself, please update it manually. Check Your Site If your site was not updated before the end of July, it is worth taking a few minutes to check nothing has been changed. Updating WordPress fixes the vulnerability, but it will not remove anything that may already have been added to your site. 1. Go to Users and check there are no administrator accounts you do not recognise. 2. Go to Plugins and check there are no plugins you did not install. 3. Check your website pages look as expected and do not redirect visitors elsewhere. 4. Change your WordPress administrator passwords. If anything looks wrong, please open a support ticket and let us know. Old or Unused WordPress Sites If you have an old, test or forgotten WordPress install that you no longer use, please delete it, including its database. Forgotten installs that never get updated are one of the most common ways websites are compromised. Need Help? WordPress have a simple step by step guide to updating here: https://wordpress.org/documentation/article/updating-wordpress/ |

