WATERCOOLER

A Critical WordPress Bug Let Hackers Take Over Sites With No Password

Ben Foord, author
Ben Foord
· 2 min read

On 17 July 2026, security researchers disclosed two flaws in WordPress core - tracked as CVE-2026-63030 and CVE-2026-60137 - which when chained together let an attacker with no account, no password, and no plugin needed take full control of a WordPress site remotely. WordPress.org shipped emergency patches the same day (versions 6.8.6, 6.9.5, or 7.0.2 depending on which release line a site was on) and pushed them out as forced automatic updates.

Within days, multiple independent security firms confirmed real-world exploitation: attackers used the flaw to create over 100 fake administrator accounts, install malicious plugins, and in some cases plant remote-access malware. Exact current numbers of compromised sites are not settled. One industry sample of roughly 125,000 sites found about 82 percent had been patched as of early August - meaning a meaningful minority were still exposed - and the full scale of successful break-ins has not been independently tallied.

Why it matters if you run a business

WordPress runs a very large share of small business websites worldwide, whether built directly, through a web host's one-click installer, or by a freelancer or agency who set it up and moved on. This bug did not require a stolen password or a targeted attack. It worked against any unpatched site sitting on the open internet - exactly the kind of quiet, unglamorous website a small business owns and rarely thinks about after launch.

The practical risk is not just defacement. A compromised site can be used to serve malware to your own customers, get blacklisted by Google and browsers (which kills search traffic and shows visitors a dangerous-site warning), or quietly host a backdoor an attacker returns to later. If nobody has actively checked whether your site auto-updated, that is worth resolving this week rather than assuming your host handled it.

Questions worth asking

  • Has our WordPress site - or our web host or agency - applied the July 2026 security update (version 6.9.5, 7.0.2, or 6.8.6 depending on what we were running)?
  • Do we have WordPress automatic updates switched on, or does someone have to remember to update it manually?
  • Even if we think we are patched, can someone check the site for administrator accounts we do not recognise, or plugins we did not install, as a precaution?

One security sample found roughly 18 percent of WordPress sites were still unpatched against a bug that needs no password to take over a site - weeks after the fix shipped as an automatic update.

Sources

The fast way to check the rest

Patching WordPress is step one. AuditCrow's free scan then checks the technical foundations of the page itself - HTTPS, redirects, robots, and more - so you can see what else is quietly broken after the emergency update.

Get notified when scans reopen
Join the waitlist and we'll tell you when they're back.
Join Waitlist
Filed under: Watercooler · Security
Join the waitlist

Be first when scans reopen

Scans are paused for a moment. Join the waitlist and we'll tell you when they're back.

We'll email you when free scans are back