Address
techniConcept SàrlRue de l'Ancien Comté 33
CH-1635  La Tour-de-TrĂȘme

WordPress 7.0.2: Security Vulnerabilities Actively Exploited

On July 17, 2026, WordPress released version 7.0.2 to fix two major security vulnerabilities, including a critical flaw that could allow an attacker to take control of a website. These vulnerabilities have already been exploited in real-world attacks, highlighting the importance of applying security updates quickly.

Razvan OpreaWord Press //
e-commerce
#WordPress
WordPress 7.0.2 security vulnerability and security release

What security vulnerabilities does WordPress 7.0.2 fix?

The two vulnerabilities are identified as CVE-2026-60137 and CVE-2026-63030.

Behind these technical names are two weaknesses that become particularly dangerous when combined. They can allow an attacker to access sensitive information and, under certain conditions, execute actions directly on the server hosting WordPress.

This attack method has been nicknamed “wp2shell.”

Put simply: an attacker may be able to take control of a WordPress website without necessarily knowing the administrator’s password.

One point is particularly important: these vulnerabilities do not originate from a plugin or theme. They directly affect WordPress core.

Have these WordPress vulnerabilities actually been exploited?

Yes.

Following the release of the security fixes, cybersecurity researchers quickly observed exploitation attempts.

The vulnerabilities were also listed by the CISA (Cybersecurity and Infrastructure Security Agency) among vulnerabilities known to be actively exploited.

We are therefore not dealing with a vulnerability demonstrated only in a laboratory: it has actually been used to attack WordPress websites.

Bitdefender security researchers also analysed a server compromised using this attack method.

How can you tell if a WordPress website has been compromised?

Analysis of these attacks provides a concrete picture of what “taking control” of a website can actually mean.

Observed behaviour included the creation of unauthorised WordPress administrator accounts and the installation of malicious plugins.

Once an attacker has administrator privileges, they have extensive control over the website. They can modify the site, create additional users, or install plugins that may allow them to maintain access.

During recent interventions on compromised WordPress websites, we have also encountered some of these symptoms: unknown user accounts appearing in WordPress and plugins that the website owners had never installed.

This does not mean that these websites were necessarily compromised through this specific vulnerability. Other types of attacks can produce similar symptoms.

In any case, an unknown administrator account, an unfamiliar plugin, or unexplained file modifications should be treated as a warning sign.

Can a small WordPress website be attacked?

Yes. A large proportion of attacks against WordPress websites are automated.

Attackers do not necessarily target a specific company. Automated tools scan the Internet for websites running versions with known vulnerabilities.

A small business, association, or self-employed professional can therefore be targeted just like a much larger organisation.

The attacker may not be interested in your company specifically, but in the vulnerability present on your website.

Is updating WordPress enough?

If your website is running a vulnerable version, installing the patched version should be the priority.

However, it is important to distinguish between a vulnerable website and an already compromised website.

Running a vulnerable version does not automatically mean that your WordPress website has been hacked. However, if an attacker gained access before the security update was installed, updating WordPress may not be enough.

If an administrator account was created, a malicious plugin installed, or files modified, these elements may still be present after WordPress has been updated.

If you have any doubts, you should at least check:

  • administrator accounts;
  • installed plugins;
  • recently modified files;
  • server logs, when available;
  • website backups.

These checks are only a first step and do not replace a full security analysis when suspicious activity has been detected.

Is your WordPress website affected?

The vulnerabilities fixed in WordPress 7.0.2 demonstrate how quickly a security flaw can become a real-world threat.

A WordPress security update should therefore not be postponed.

If you notice an unknown administrator account, a plugin you never installed, or other unexplained changes, techniConcept can carry out a security check of your WordPress website, look for the main signs of compromise and, if necessary, clean and secure the website.

Frequently asked questions

Is WordPress 7.0.1 affected by these vulnerabilities?

Yes. The security fixes were included in WordPress 7.0.2. A website still running WordPress 7.0.0 or 7.0.1 should therefore be updated.

Does running a vulnerable version mean my website has been hacked?

No. A vulnerable website is not automatically a compromised website. It does, however, mean that the website has been exposed to a known vulnerability and should be updated quickly.

How can I tell if my WordPress website has been hacked?

An unknown administrator account, a plugin you did not install, modified files, or unusual redirects can all be warning signs. A more thorough security analysis is required to confirm whether a website has been compromised.

Razvan OpreaWord Press //
e-commerce
#WordPress

Share this article

Address

techniConcept SàrlRue de l'Ancien Comté 33
CH-1635  La Tour-de-TrĂȘme