On July 17, 2026, WordPress released an urgent security update fixing two serious vulnerabilities in WordPress core. One can leak private data from your database. The other can hand an attacker full control of a site.
If you’re a MalCare customer, here’s the part that matters most: your site was protected within hours of the disclosure, before you had a chance to update.
You’re already protected
As soon as the vulnerabilities were disclosed, our security team built and deployed new firewall rules (virtual patches) through Vulnerability Shield. These rules check every request before it reaches WordPress and block anything that looks like an exploit attempt.
Since then, Vulnerability Shield has already blocked over 3,000 attacks targeting these two vulnerabilities across sites on our network.
Attackers rarely reuse a published exploit as-is. So before rollout, we tested our patches against the original exploits, modified payloads, and different encodings. We also replayed normal traffic to make sure nothing on your site breaks.
What this means for you: even if you haven’t updated WordPress yet, your site is shielded. Update when you can, but you don’t need to panic.
What are these vulnerabilities?
There are two
- CVE-2026-60137 (High severity, WordPress 6.8): An SQL injection flaw that could let attackers quietly read private data from your database, like customer details and form entries.
- CVE-2026-63030 (Critical, WordPress 6.9 to 7.0.1): Combined with the first, it can let attackers run malicious code, create rogue admin accounts, redirect your visitors, or take over the site entirely.
WordPress is treating this as its highest-priority class of issue and has pushed forced automatic updates to affected sites. Version 7.0.2 (and backported fixes for older branches) contains the fix.
Why this one made headlines
Some useful context: high-severity vulnerabilities in WordPress core are genuinely rare. The vast majority of WordPress vulnerabilities, well over 90% in any given year, are found in plugins and themes, not core. WordPress core is heavily audited, and it has been years since a core flaw of this severity was exploited in the wild.
That rarity is exactly why this disclosure is getting attention.
Credit where it’s due: the SQL injection was responsibly disclosed by researchers TF1T, dtro, and haongo, and the critical takeover chain by Adam Kues of Assetnote/Searchlight Cyber. Their responsible disclosure gave the WordPress Security Team time to ship fixes before the technical details went public.
What you should still do
Virtual patches protect you from attacks going forward. They can’t undo an attack that may have landed before protection was in place. So take five minutes to:
- Confirm your site is on WordPress 7.0.2 (or the patched release for your branch). Auto-updates should have handled this, but verify.
- Run a malware scan to check for hidden backdoors or malicious code.
- Review your activity log for anything unexpected, like new admin users, plugin installs, or logins you don’t recognize.
If anything looks off, use instant cleanup or reach out to our team.
Managing client sites? Send them this
A core vulnerability of this severity will make the news. A short, proactive note reassures clients and makes your security work visible. Feel free to adapt this:
Security update: 2 major WordPress vulnerabilities. Your site is protected. On July 17, WordPress released an urgent security update fixing two core vulnerabilities that could allow attackers to steal private data or take over a site. Within hours of the disclosure, firewall protection was deployed to your site through our security partner, MalCare. These attacks were blocked before the official update was even installed. We’ve since verified your site is updated and clean. No action is needed on your end.
Looking forward
Vulnerability Shield continues to monitor traffic matching these attack patterns and will update detections as new exploit variations appear. If attackers change tactics, the rules change with them.



