The summer of 2026 proved to be a challenging time for WordPress sites: three critical updates in a month and a half, one of which included a mandatory auto-update. Let’s take a look at what happened and what site owners should check today.
Timeline
May: WordPress 7.0
On May 20, WordPress 7.0 “Armstrong” was released—the first major release of the year. Key points for site owners: The minimum PHP version has been raised to 7.4. Websites running on PHP 7.2 and 7.3 simply aren't updated to the new branch and remain without security patches.
July 17: Emergency Updates 6.9.5 and 7.0.2
Security researchers at Assetnote (Searchlight Cyber) have uncovered a vulnerability named wp2shell: remote code execution without authorization. This is the worst type of vulnerability—the attacker doesn't need a password or an account.
WordPress has released emergency updates with forced auto-updates, meaning the updates were pushed even to sites where auto-updates were disabled (official news).
August 6: 7.0.3
A release containing only security fixes — 12 vulnerabilities at a time (release analysis).
Next: 7.0.4
Prevents code execution via file uploads for users with "author" privileges or higher on sites that use Imagick and Ghostscript. If you have multiple editors or open registration, this applies to you.
Why does this apply to a standard business card website?
A common misconception: “We have a small website—who needs us?” Massive WordPress hacks never pick their victims. Here’s how it works: a public description of a vulnerability appears—within hours, scanners are launched that scan every website in a row and target those that haven’t been updated.
The situation has worsened further because WordPress 7.0 introduced the Abilities API and deeper integration with AI—attackers are also scanning these new interfaces using automated tools.
The consequences are typical and unpleasant: pages with third-party ads, redirects to external sites, spam sent from your domain, and eventually—a “dangerous site” label on Google and being removed from search results.
What to Check Today
- Kernel version. Console → Updates. The branch should be 7.0.x. If you see 6.x, you've missed at least two critical patches.
- PHP version. In the hosting control panel. 7.4 is the minimum requirement; 8.2 or 8.3 are recommended. On older versions, the website simply won't receive updates.
- Automatic kernel update are enabled, at least for security releases.
- Plugins and themes. Most security breaches occur not through the core, but through plugins. Delete anything you don't use: even inactive plugins take up space on your hard drive and are vulnerable.
- Backups. It's not that "they seem to be working," but rather that they have been verified through restoration. A backup that has never been restored is just an assumption—not a backup.
- Unnecessary entry points. XML-RPC, open registration, old accounts belonging to former employees, files containing passwords and keys in public folders.
About files that are “just lying around”
Another common problem is storing file backups directly in the website folder: functions.php.bak, config-old.php, dump.sql. The server does not execute these files; instead, it returns them as plain text: anyone who guesses the filename can read your code—and sometimes even gain access to the database or API keys.
The rule is simple: backups are stored outside the site's root folder. Always.
What to Do If You're Afraid to Update
It's an understandable concern: you update something, and something breaks. Here's what to do:
- make a complete copy—files and database;
- Update it first on a test copy; with web hosting providers, this is usually done with a single click;
- Check the essentials: forms, shopping cart, payment, and admin panel;
- and only then update the combat website.
Keep in mind, however, that according to statistics, after the release of 7.0, approximately 46% websites automatically updated within a week without any issues. The risk of breaking a website with an update is significantly lower than the risk of not updating it.
In Brief
Three critical releases in a month and a half—that’s not an anomaly, but the new norm. A website without updates doesn’t “stay the same”; it becomes more vulnerable every day.
If you don't want to keep track of this yourself, we'll take care of the websites for you technical support, including those performed by other contractors: updates, verified backups, monitoring, and status audits. You can start with an audit—you’ll receive a list of issues with an explanation of what’s critical and what can wait.
А якщо ви тільки плануєте новий сайт — робимо під ключ і одразу налаштовуємо оновлення й бекапи: calculate the cost.


