Skip to content
Beveiligingsnieuws

Severe WordPress Core vulnerabilities: install updates

ernstige kwetsbaarheden WordPress core

Severe WordPress Core vulnerabilities have been fixed with security updates, and misuse has been observed shortly after publication. If your website is managed with WordPress Core, the most important step is to update without delay. Doing so helps limit the risk that an attacker can take advantage of the flaws.

In this alert, the NCSC describes two vulnerabilities, outlines which WordPress versions are affected, and explains what you should do next to protect your site.

Why this alert matters

The NCSC evaluates the combined impact of the two issues as severe. That severity is not only about technical risk, but also about real-world behavior: shortly after the vulnerabilities were published, attackers were already observed exploiting them.

WordPress is widely used to manage websites. When a core component has security problems, the potential consequences can extend beyond a single site—especially if many installations share similar configurations.

Which vulnerabilities were patched

Two security issues in WordPress Core are addressed by the available updates:

  • CVE-2026-60137 (CVSS score 5.9)
  • CVE-2026-63030 (CVSS score 9.8)

The most critical one, CVE-2026-63030, enables an attacker to execute malicious code remotely without logging in, using a specially crafted HTTP request. The second vulnerability further increases the overall abuse potential.

Potential impact if your site is not updated

If an attacker successfully exploits these weaknesses, the outcome can be serious. The NCSC notes that a successful attack may allow an attacker to take control of your website.

Depending on what the attacker can reach and what your site exposes, other results can include theft of data or making the website unavailable. In practice, that can lead to downtime, reputational harm, and additional recovery costs.

Which WordPress versions are affected

Not every WordPress release carries the same exposure. According to the NCSC, the following versions are vulnerable:

  • WordPress 6.9 is vulnerable to both security issues. The fixed release is 6.9.5.
  • WordPress 6.8 is vulnerable only to the first issue. The fixed release is 6.8.6.
  • WordPress 7.1 beta is vulnerable to both issues. The fixed version mentioned is 7.1 beta2.
  • WordPress 7 versions for 7.0.2 are vulnerable to both vulnerabilities.
  • WordPress versions older than 6.8 are not vulnerable, per the alert.

If you want a quick sanity check: make sure your installation is on the patched version for your branch. If you’re unsure which exact version you run, you need to confirm it before deciding what update to install.

What you should do now

1) Install the available security updates

The NCSC’s primary recommendation is straightforward: install the security updates for the affected WordPress Core versions as soon as possible. Since misuse has already been observed, delaying updates increases the window for opportunistic attacks.

Updating reduces the risk that your site remains reachable through the vulnerable HTTP handling that the most critical issue introduces.

2) Check your WordPress version

If you’re not sure which version is currently installed, verify it before proceeding. If you manage WordPress yourself, check the version shown in the administrative interface or your deployment records. If you rely on an IT partner or hosting provider, ask them to confirm the installed version.

The alert also suggests contacting your IT service provider or hosting party if you’re uncertain about your version.

3) If you cannot update immediately, discuss temporary measures

Sometimes immediate patching is not feasible due to change management, deployment constraints, or availability requirements. In that case, the NCSC advises discussing temporary measures with your IT service provider.

The goal of temporary steps is to reduce the likelihood of exploitation until you can install the official security update. Your provider can assess what is safe in your environment, based on your hosting setup and threat exposure.

How to plan a safer update without creating extra risk

Even though the main message is to update quickly, it’s still wise to update in a controlled way. Consider the following practical approach:

  • Schedule the update as high priority, given the observed misuse.
  • Coordinate with your hosting provider if your environment requires special deployment steps.
  • Test after updating to confirm your site and key features still work as expected.
  • Monitor logs for unusual requests, especially around the time of update rollout.

While these steps don’t replace patching, they help ensure the update succeeds and any unexpected behavior is detected promptly.

Frequently asked questions

Is WordPress older than 6.8 affected?

According to the NCSC, WordPress versions older than 6.8 are not vulnerable to these issues.

Do I need to update even if my site “seems fine”?

Yes. If your installed WordPress version is within the vulnerable range described above, updating is the recommended action. The alert emphasizes that misuse was observed shortly after disclosure, so you should assume exploitation attempts may already be occurring.

What makes CVE-2026-63030 especially dangerous?

The NCSC notes that this vulnerability allows remote execution of malicious code without an attacker needing to log in, via a specially crafted HTTP request.

Conclusion: update now to reduce misuse risk

Severe WordPress Core vulnerabilities have been identified and patched, and the NCSC reports active exploitation shortly after publication. To protect your website, install the relevant security updates for your WordPress version—such as 6.9.5 for the 6.9 line or 6.8.6 for the 6.8 line—and confirm you’re on the fixed releases.

If you’re not able to update right away, involve your IT service provider or hosting party to plan temporary risk-reduction steps until the official update is applied.

Source: https://www.ncsc.nl/alerts/ernstige-kwetsbaarheden-in-wordpress-core-installeer-updates