Critical Severity Vulnerability in latest versions of WordPress

July 20, 2026

This is a notice from the Information Security Office to alert you to a critical vulnerability that impacts WordPress, a common website management platform[1]. Please share this alert internally with IT admins and service owners who run the product so they are aware and know what actions to take to address this vulnerability.

SUMMARY

ISO is aware of two vulnerabilities, with Critical and High Severity, that affect WordPress 6.8, 6.9, 7.0, and 7.1 (beta). These vulnerabilities take advantage of SQL Injection issues in the user interface and REST API, allowing Remote Code Execution in the case of the API vulnerability.

IMPACT

If exploited, remote users (potentially unauthenticated users) could run commands against the site, including modifying content and uploading and executing malicious code.

WHAT IS VULNERABLE

Vulnerable versions include:

  • WordPress 7.0 before 7.0.2
  • WordPress 6.9 before 6.9.5
  • WordPress 6.8 before 6.8.6
  • WordPress 7.1 beta

WordPress versions earlier than 6.8 are NOT impacted.

RECOMMENDATIONS

  1. Upgrade to a patched version of WordPress as soon as possible:

    1. WordPress 7.0.2

    2. WordPress 6.9.5

    3. WordPress 6.8.6

    4. WordPress 7.1 beta2

REFERENCES

  1. https://wordpress.org/news/2026/07/wordpress-7-0-2-release/

  2. https://wordpress.org/documentation/wordpress-version/version-7-0-2/

If you have any questions about the vulnerability or would like some assistance patching or mitigating it, please contact security@berkeley.edu.