{"id":14754,"date":"2026-07-20T12:38:24","date_gmt":"2026-07-20T12:38:24","guid":{"rendered":"https:\/\/wpm.si\/?p=14754"},"modified":"2026-07-20T12:38:24","modified_gmt":"2026-07-20T12:38:24","slug":"wordpress-702-security-update","status":"publish","type":"post","link":"https:\/\/wpm.si\/en\/wordpress-development\/wordpress-702-security-update\/","title":{"rendered":"WordPress 7.0.2 Security Update: Critical Flaw, Update Now"},"content":{"rendered":"<p><strong>WordPress has released an emergency security update, and this one deserves your immediate attention.<\/strong> On July 17, the WordPress security team published <a href=\"https:\/\/wordpress.org\/news\/2026\/07\/wordpress-7-0-2-release\/\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>WordPress 7.0.2<\/strong><\/a>, which fixes a critical vulnerability that lets an attacker take over a standard WordPress installation without logging in. No plugins or themes need to be involved.<\/p>\n<p>The severity shows in an unusual step: <strong>WordPress.org has enabled forced automatic updates<\/strong> for all sites running affected versions. If your site is on a vulnerable version, update today.<\/p>\n<h1>What Happened<\/h1>\n<p>The critical issue combines a REST API batch-route confusion with SQL injection, which together allow remote code execution. The entry point is the REST API batch endpoint (<code>\/wp-json\/batch\/v1<\/code>), present on every standard WordPress installation. Put simply, an anonymous attacker could gain full control of an unpatched website.<\/p>\n<p>Security researcher Adam Kues of Searchlight Cyber reported the flaw responsibly, so the WordPress team had time to prepare fixes before anything went public. The same release also patches a separate SQL injection issue of high severity.<\/p>\n<h1>Which Versions Are Affected<\/h1>\n<ul>\n<li><strong>WordPress 7.0.0 to 7.0.1<\/strong> \u2192 update to <strong>7.0.2<\/strong><\/li>\n<li><strong>WordPress 6.9.0 to 6.9.4<\/strong> \u2192 update to <strong>6.9.5<\/strong><\/li>\n<li><strong>WordPress 6.8.x<\/strong> \u2192 not affected by the takeover flaw, but exposed to the separate SQL injection issue \u2192 update to <strong>6.8.6<\/strong><\/li>\n<li><strong>WordPress 7.1 beta<\/strong> \u2192 fixed in <strong>beta 2<\/strong><\/li>\n<li><strong>Versions before 6.8<\/strong> \u2192 not affected by either issue<\/li>\n<\/ul>\n<p><strong>Don&#8217;t assume your site updated itself. Check.<\/strong> Log in to your WordPress dashboard and look at the version under Updates. Forced auto-updates cover most sites, but installations with disabled background updates or custom hosting setups can be left behind.<\/p>\n<h1>What to Do Right Now<\/h1>\n<p><strong>1. Update WordPress.<\/strong> Go to Dashboard \u2192 Updates \u2192 Update Now, or download <a href=\"https:\/\/wordpress.org\/download\/\" target=\"_blank\" rel=\"noopener noreferrer\">the latest version<\/a> from WordPress.org.<\/p>\n<p><strong>2. If you really can&#8217;t update yet<\/strong>, there are temporary measures: block unauthenticated access to the REST API, or block the path <code>\/wp-json\/batch\/v1<\/code> and the query parameter <code>rest_route=\/batch\/v1<\/code> at your firewall. Both can break legitimate REST API traffic, so use them only as short-term cover until you patch.<\/p>\n<p><strong>3. After updating, take a look around.<\/strong> If your site ran an affected version for a few days, check for unexpected admin users, recently modified files, or unfamiliar scheduled tasks. If anything looks off, ask your developer or maintenance provider to dig in.<\/p>\n<h1>How We&#8217;re Handling It at WPM<\/h1>\n<p>All websites covered by our <a href=\"https:\/\/wpm.si\/en\/maintenance-and-support-packages\/\">maintenance and support packages<\/a> have been updated to patched versions, and we&#8217;re keeping an eye on them as an extra precaution. Situations like this are the whole point of a maintenance plan. When a critical vulnerability drops, sites that get patched within hours stay safe, while sites that wait become targets.<\/p>\n<p>If your website isn&#8217;t under active maintenance and you&#8217;re not sure where you stand, check your WordPress version today, or <a href=\"https:\/\/wpm.si\/en\/contact\/\">get in touch<\/a> and we&#8217;ll help you verify.<\/p>\n<h1>Looking Ahead<\/h1>\n<p>Critical vulnerabilities in WordPress core are rare, and the response to this one shows the security model working as intended. The flaw was reported privately, fixes were backported across three release branches, and forced updates went out to protect sites at scale, all within days.<\/p>\n<p><strong>Still, no security process replaces the basics: keep your WordPress core, plugins, and themes up to date, and know who&#8217;s watching your site when an update like this lands.<\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>WordPress released an emergency update on July 17 fixing a critical vulnerability that allows attackers to take over unpatched sites. Here&#8217;s which versions are affected, what to do right now, and how to check if your site is safe.<\/p>\n","protected":false},"author":1,"featured_media":14440,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[57,25],"tags":[],"class_list":["post-14754","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-maintenance-and-support","category-wordpress-development"],"_links":{"self":[{"href":"https:\/\/wpm.si\/en\/wp-json\/wp\/v2\/posts\/14754","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wpm.si\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wpm.si\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wpm.si\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/wpm.si\/en\/wp-json\/wp\/v2\/comments?post=14754"}],"version-history":[{"count":2,"href":"https:\/\/wpm.si\/en\/wp-json\/wp\/v2\/posts\/14754\/revisions"}],"predecessor-version":[{"id":14756,"href":"https:\/\/wpm.si\/en\/wp-json\/wp\/v2\/posts\/14754\/revisions\/14756"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/wpm.si\/en\/wp-json\/wp\/v2\/media\/14440"}],"wp:attachment":[{"href":"https:\/\/wpm.si\/en\/wp-json\/wp\/v2\/media?parent=14754"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wpm.si\/en\/wp-json\/wp\/v2\/categories?post=14754"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wpm.si\/en\/wp-json\/wp\/v2\/tags?post=14754"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}