18 July 2026
Reference: CVE-2026-63030
1. What is being reported?
Researchers have discovered a critical flaw in certain WordPress versions that combines two issues to let hackers inject malicious commands into the website’s database and potentially take full control of the site remotely.
2. What this means in plain English
If your website uses the affected WordPress versions, attackers might exploit this flaw to steal information, disrupt your site, or use it to attack others. This risk is especially serious because it allows remote control without needing direct access.
3. Could this affect a small business?
Small businesses, charities, clubs, or any organisation using WordPress versions before 6.9.5 or 7.0.2 could be affected. If you use a different website platform or have updated WordPress recently, you are likely not at risk.
4. What to do now
- Check which WordPress version your website is running.
- If using an affected version, update WordPress to the latest available version immediately.
- Contact your website manager or hosting provider to confirm updates have been applied.
- Monitor your website for unusual activity and review security settings.
5. Ask your IT provider
Can you confirm if our WordPress website is updated to a version that fixes the CVE-2026-63030 vulnerability and that no related security risks remain?
6. Bottom line
Keep your WordPress site updated to protect against this critical security flaw and prevent hackers from taking control.
Information based on NVD, CISA KEV, and reputable security reporting.