This story first broke on July 17, 2026.
A serious flaw was found in WordPress itself, not a plugin. It can be exploited with no login required, and a public proof-of-concept is already circulating.
What to Do
1. Check your WordPress version. Affected versions are 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1.
2. Update WordPress core immediately if you’re on an affected version, an emergency patch has already been released.
3. Don’t assume updated plugins mean you’re safe. This flaw lives in WordPress core, so a fully updated plugin list doesn’t protect against it.
Why This One Is Different
Most WordPress security stories involve a specific plugin. This one is in WordPress core itself, the software running every WordPress site regardless of which plugins are installed. The flaw allows an attacker to read the site’s database, including admin password hashes, without logging in first. Because working attack code is already public, this isn’t a theoretical risk, it’s actively usable right now against any unpatched site.
A core vulnerability like this affects every WordPress site on an affected version, from a personal blog to a full ecommerce store, regardless of how well the rest of the site is maintained. Confirming your WordPress version is current is worth doing today, not on the next regular check-in.
Source: Rapid7