WordPress released security updates on July 17, 2026 for CVE-2026-63030 and CVE-2026-60137. CISA added both vulnerabilities to the Known Exploited Vulnerabilities catalog on July 21. Updating WordPress closes the known flaws; it does not remove a shell or account created before the update.
Current as of 2026-08-15
WordPress 7.0.2 release guidance identifies fixed releases 7.0.2, 6.9.5, and 6.8.6 and says versions before 6.8 are unaffected. WordPress initiated forced background updates for affected branches.
Decision summary
- Verify the installed WordPress core version rather than trusting an update notification.
- Confirm every production, staging, development, and abandoned instance.
- Investigate for persistence when an affected site was exposed before patching.
- Update plugins, themes, PHP, and hosting controls separately; the core update does not remediate unrelated risk.
Resolve the exact core version
Record the WordPress version from the running site and deployment artifact. Supported fixed branches are 7.0.2, 6.9.5, and 6.8.6. Versions before 6.8 are not affected by these two CVEs, but they may be unsupported or exposed to other vulnerabilities.
Verify every copy
- Public production sites.
- Staging and development hosts.
- Old domains and subdomains.
- Temporary migration copies.
- Backup restorations and golden images.
- Sites operated by a marketing or hosting vendor.
Patch safely
- Create a current backup and verify restore access.
- Apply the supported WordPress core update.
- Confirm the running version and filesystem state.
- Test login, forms, ecommerce, integrations, and scheduled jobs.
- Keep rollback evidence while checking for compromise.
Look for persistence
Review administrator accounts, recently modified PHP files, uploads containing executable content, plugins, themes, scheduled tasks, web-server configuration, access logs, outbound traffic, and hosting control-panel activity. Compare core files with trusted packages. Preserve evidence before deleting suspicious artifacts.
Escalate when evidence appears
A web shell or unauthorized administrator is an incident, not a cleanup ticket. Isolate the site where safe, preserve logs and files, rotate exposed credentials and secrets, assess connected databases and services, and rebuild from a trusted source when integrity cannot be established.
For related guidance from ITECS, see ITECS cybersecurity services.
Sources and update trigger
Review trigger: Recheck the WordPress release post and CISA KEV entry when new fixed releases, exploitation details, or indicators appear.
continue reading
More ITECS blog articles
About ITECS Team
The ITECS team consists of experienced IT professionals dedicated to delivering enterprise-grade technology solutions and insights to businesses in Dallas and beyond.
View full profile and articles