WordPress Deploys Critical Security Patches to Protect Millions of Websites Worldwide

WordPress Deploys Critical Security Patches

Following the discovery of two core vulnerabilities dubbed "wp2shell" (CVE-2026-63030 and CVE-2026-60137), the WordPress Security Team acted swiftly to safeguard website owners globally. Official patches—including versions 6.8.6, 6.9.5, and 7.0.2—were released immediately, with forced automatic updates triggered across supported platforms to halt exploitation attempts before they could take hold.

Major cybersecurity providers, including Wordfence and Cloudflare, confirmed that proactive firewall protections and auto-patches successfully shielded millions of web properties. While active network scans continue targeting unpatched legacy sites, webmasters can secure their digital footprint in seconds simply by confirming their platform updated to the latest build.

Site admins can verify their patch status inside the WordPress dashboard under Dashboard > Updates. Taking 30 seconds to confirm your auto-update setting ensures complete protection and peace of mind.

Source: wordpress-7-0-2-release