The vulnerability was classified as critical, with a severity score of 9.8 out of 10. It affected WordPress versions 6.9.0 through to 7.0.1 and could, under certain circumstances, allow an attacker to take control of a website without needing a username or password.
Secure updates have now been released, and all websites hosted on Cogio’s servers have been reviewed and protected against the vulnerability.
After being alerted to the issue over the weekend, we immediately began reviewing every website hosted on our platform.
This involved identifying websites running an affected version of WordPress, checking them for signs of unauthorised access and updating them to a secure version.
During these checks, we discovered that a small number of websites had already been compromised, demonstrating how quickly attackers had begun taking advantage of the vulnerability.
Where a website was affected, we took it offline to prevent further damage, investigated the compromise and safely restored it to working order. We are contacting the owners of each affected website directly to explain what happened and help them with any relevant next steps.
All websites hosted on Cogio’s servers have now been secured against this vulnerability. Customers do not need to update WordPress themselves.
The vulnerability affected a part of WordPress that allows websites to receive and process requests from other systems.
WordPress would normally check these requests to confirm that they are valid and that the person or system making them has permission to carry out the requested action.
However, researchers discovered that a specially prepared request could confuse these checks. When combined with a separate database vulnerability, this could allow an attacker to make WordPress run malicious instructions on the website’s server.
This type of vulnerability is known as remote code execution. In simple terms, it means that someone elsewhere on the internet could potentially make an affected website or hosting account run code chosen by the attacker.
Several factors made this an especially dangerous security issue.
An attacker would not necessarily need a WordPress username or password. The attack could be carried out remotely through the website without first gaining access to its administration area.
The attack also did not require a website owner, employee or visitor to click a link, open a file or approve anything. This meant that attempts could be automated and directed at large numbers of websites in a relatively short period.
If successfully exploited, an attacker could potentially:
This does not mean that every website using an affected version of WordPress was compromised. A vulnerability provides attackers with a possible route into a website, but its presence alone is not proof that an attack was successful.
However, because an attacker could potentially gain significant control without needing login details or any action from the website owner, the vulnerability required an immediate response.
WordPress released version 7.0.2 on 17 July 2026 to correct the vulnerability. WordPress 6.9.5 was also released for websites remaining on the previous major version.
The secure versions are:
WordPress 6.9.5 or later
WordPress 7.0.2 or later
Websites using WordPress 6.9.0 to 6.9.4, or WordPress 7.0 to 7.0.1, should be updated immediately.
Anyone responsible for a WordPress website that is not hosted and maintained by Cogio should check which version it is currently running.
Updating WordPress is the most important immediate step. However, simply installing the latest version may not be enough if the website was compromised before the update was applied.
Website owners should also look for possible signs of unauthorised access, including:
Themes and plugins should also be updated, and a reliable website backup should be kept in case the site needs to be restored.
No website platform can be guaranteed to remain permanently free from newly discovered vulnerabilities. Even widely used and actively maintained systems such as WordPress can be affected by serious security issues.
Website security therefore depends on regular maintenance, reliable backups, monitoring security announcements and responding quickly when new threats are discovered.
Cogio’s current range of hosting and maintenance services include ongoing software updates and security oversight. This allows us to respond to issues such as this without customers having to monitor technical security reports or manage urgent updates themselves.
If your website is running an affected version of WordPress, has not been updated or may already have been compromised, it is important to act quickly.
Cogio can help you:
Concerned that your website may be vulnerable or has already been hacked?
Contact us for help assessing the problem, securing your website and protecting your visitors.