A serious security vulnerability has been identified in recent versions of WordPress, the website management system used by millions of businesses and organisations around the world.

The vulnerability was classified as critical, with a severity score of 9.8 out of 10. It affected WordPress versions 6.9.0 through to 7.0.1 and could, under certain circumstances, allow an attacker to take control of a website without needing a username or password.

Secure updates have now been released, and all websites hosted on Cogio’s servers have been reviewed and protected against the vulnerability.

Our response

After being alerted to the issue over the weekend, we immediately began reviewing every website hosted on our platform.

This involved identifying websites running an affected version of WordPress, checking them for signs of unauthorised access and updating them to a secure version.

During these checks, we discovered that a small number of websites had already been compromised, demonstrating how quickly attackers had begun taking advantage of the vulnerability.

Where a website was affected, we took it offline to prevent further damage, investigated the compromise and safely restored it to working order. We are contacting the owners of each affected website directly to explain what happened and help them with any relevant next steps.

All websites hosted on Cogio’s servers have now been secured against this vulnerability. Customers do not need to update WordPress themselves.

What happened?

The vulnerability affected a part of WordPress that allows websites to receive and process requests from other systems.

WordPress would normally check these requests to confirm that they are valid and that the person or system making them has permission to carry out the requested action.

However, researchers discovered that a specially prepared request could confuse these checks. When combined with a separate database vulnerability, this could allow an attacker to make WordPress run malicious instructions on the website’s server.

This type of vulnerability is known as remote code execution. In simple terms, it means that someone elsewhere on the internet could potentially make an affected website or hosting account run code chosen by the attacker.

Why was the vulnerability so serious?

Several factors made this an especially dangerous security issue.

An attacker would not necessarily need a WordPress username or password. The attack could be carried out remotely through the website without first gaining access to its administration area.

The attack also did not require a website owner, employee or visitor to click a link, open a file or approve anything. This meant that attempts could be automated and directed at large numbers of websites in a relatively short period.

If successfully exploited, an attacker could potentially:

  • Take control of the website
  • Access, alter or delete information
  • Install malicious files
  • Create hidden methods of regaining access
  • Redirect visitors to other websites
  • Distribute spam or malware
  • Disrupt or disable the website

This does not mean that every website using an affected version of WordPress was compromised. A vulnerability provides attackers with a possible route into a website, but its presence alone is not proof that an attack was successful.

However, because an attacker could potentially gain significant control without needing login details or any action from the website owner, the vulnerability required an immediate response.

What did WordPress do?

WordPress released version 7.0.2 on 17 July 2026 to correct the vulnerability. WordPress 6.9.5 was also released for websites remaining on the previous major version.

The secure versions are:

WordPress 6.9.5 or later
WordPress 7.0.2 or later

Websites using WordPress 6.9.0 to 6.9.4, or WordPress 7.0 to 7.0.1, should be updated immediately.

What should other WordPress website owners do?

Anyone responsible for a WordPress website that is not hosted and maintained by Cogio should check which version it is currently running.

Updating WordPress is the most important immediate step. However, simply installing the latest version may not be enough if the website was compromised before the update was applied.

Website owners should also look for possible signs of unauthorised access, including:

  • Unexpected administrator accounts
  • Unfamiliar files or plugins
  • Altered pages or website content
  • Unexplained redirects
  • Security warnings from browsers or search engines
  • Unusual behaviour within the website
  • Unexpected changes to hosting or server files

Themes and plugins should also be updated, and a reliable website backup should be kept in case the site needs to be restored.

The importance of ongoing website maintenance

No website platform can be guaranteed to remain permanently free from newly discovered vulnerabilities. Even widely used and actively maintained systems such as WordPress can be affected by serious security issues.

Website security therefore depends on regular maintenance, reliable backups, monitoring security announcements and responding quickly when new threats are discovered.

Cogio’s current range of hosting and maintenance services include ongoing software updates and security oversight. This allows us to respond to issues such as this without customers having to monitor technical security reports or manage urgent updates themselves.

Has your WordPress website been affected?

If your website is running an affected version of WordPress, has not been updated or may already have been compromised, it is important to act quickly.

Cogio can help you:

  • Secure and update your WordPress website
  • Investigate possible signs of unauthorised access
  • Identify and remove malicious files
  • Remove hidden access points left by attackers
  • Restore the website to a clean and secure state
  • Put appropriate backups and ongoing protection in place

Need help from an expert?

Concerned that your website may be vulnerable or has already been hacked?

Contact us for help assessing the problem, securing your website and protecting your visitors.