18/08/2026
🚨 WordPress users: check your website security
A serious WordPress vulnerability was publicly disclosed on July 21 and is currently being exploited at scale.
Affected versions:
WordPress 6.9.0–6.9.4 → update to the latest version
WordPress 7.0.0–7.0.1 → update to the latest version
The vulnerability does not require a password or user account, which means automated scanners can find vulnerable websites without any login.
If you use WordPress, go to Dashboard → Updates and check your version.
⚠️ Important: updating your website closes the vulnerability, but it does not remove an infection if the website has already been compromised.
If your website has been running an affected version, check for unusual activity as well. For example, 👉 search Google for: site:yourdomain.com and look for pages or titles you don't recognize. You can also check Google Search Console → Security & Manual Actions.
We've put together a few simple security checks that can help reduce the risk of website attacks — see below. 👇
If you find anything suspicious or aren't sure whether your website is affected, feel free to reach out to us.