WordPress News

WordPress News: Critical Core Vulnerability Patched (Week of 21 July 2026)

WHWynand HoltzhausenJul 21, 20264 min read
WordPress News: Critical Core Vulnerability Patched (Week of 21 July 2026)

This week had one story that mattered more than the rest: a critical WordPress core vulnerability chain that attackers started exploiting within days of the patch going out. Alongside it, hundreds of new plugin vulnerabilities landed, and WooCommerce quietly admitted that even AI support tools are only as good as the documentation behind them. Here's what's actually worth your attention.

Update WordPress core right now if you haven't already

On July 17, 2026, the WordPress Security Team released versions 7.0.2, 6.9.5, and 6.8.6 to patch two vulnerabilities that can be chained together into unauthenticated remote code execution (WordPress.org news). The first, CVE-2026-60137, is a SQL injection flaw present in core since version 6.8. The second, CVE-2026-63030, lets an attacker abuse the REST API's batch request endpoint to turn that SQL injection into full remote code execution. Wordfence considered it serious enough to withhold technical details while sites update (Wordfence PSA). By July 20, TechCrunch reported that multiple security firms had already observed active exploitation in the wild, with one researcher estimating tens of millions of sites were still vulnerable (TechCrunch).

What this means for you: If your site runs WordPress 6.8 through 7.0.1, confirm right now that it has actually updated to 6.8.6, 6.9.5, or 7.0.2. WordPress forced this update on most hosts automatically, but "most" is not "all", and a forced update can still fail silently. Log into your dashboard and check the version number under Updates. If something looks broken after an unexpected update, our guide to fixing the WordPress critical error walks through the recovery steps. This is exactly the kind of vulnerability that a proper security setup exists to catch before it turns into a crisis.

Your plugins are still the bigger day-to-day risk

Wordfence logged 267 new plugin and theme vulnerabilities in a single week (July 6 to 12), 13 of them rated critical, including a 9.8-severity flaw in Super Forms and high-severity issues in Membership For WooCommerce, WPFunnels, and ProfileGrid (Wordfence weekly vulnerability report). None of this made headlines the way the core vulnerability did, but plugins remain the entry point for the overwhelming majority of WordPress compromises, not core itself.

What this means for you: Core now patches itself on most hosts. Plugins don't, unless you've deliberately set them to. If your site runs Super Forms, Membership for WooCommerce, WPFunnels, or ProfileGrid, update them today. More broadly, this week is a good reminder that keeping a WordPress site secure isn't a one-time task, it's a constant stream of small updates. That's exactly why a maintenance plan exists: so someone is checking this list every single week instead of you.

AI chatbots are only as accurate as the manual they read

WooCommerce published an unusually candid post this week, admitting that its AI support assistant once confidently told a merchant to click a "Simple Payment" button that no longer existed, because the underlying documentation hadn't been updated after a product change (WooCommerce blog). Their fix was to build an automated system that flags outdated docs for a human writer to review, essentially training a small squad of proofreading droids to keep the manuals current.

What this means for you: If your team leans on AI chatbots, WooCommerce's or anyone else's, for how-to answers, treat a confident-sounding reply as a starting point, not gospel. If the instructions don't match what's actually on your screen, the documentation is probably out of date, not you. It's a small story, but it's a useful reminder that AI support tools inherit the same maintenance problem every WordPress site has: nothing stays accurate on its own.

This week really came down to one thing: patch fast, because attackers are already moving, and they don't wait for a convenient time to do it. If nobody on your team is checking WordPress core and plugin updates every week, that's a gap worth closing now rather than after an incident. Our maintenance plan covers exactly this, including monitoring and updates, so it doesn't fall on you to catch it.

May the Code Be With You.

Share transmission
inX
WH

Wynand Holtzhausen

Senior engineer at WordPress Pro. Rescues struggling sites, rebuilds them stronger, and writes about how it is done.

Related transmissions