On July 17, 2026, WordPress released an emergency security update. If you run a WordPress site, this is worth your attention.

Here’s what happened, what it means, and how we’re handling it at NgageContent.

Let’s get straight to some good news. If you are an active client of ours with a retainer or website maintenance, we’re already taking care of this for you!

What Was the Security Issue?

Security researchers found two separate weaknesses in WordPress. Either one would have been a problem on its own. Chained together, they gave attackers a way to take over a vulnerable site without needing a password or a login.

In simple terms: one flaw lets bad actors sneak commands into a site’s database. The other let them reach a part of WordPress that should have been off limits. Together, these two issues opened a door that let attackers walk right in and take control.

Which WordPress Versions Were Affected?

This issue impacted WordPress versions 6.8 through 7.0.1, but not equally. Sites on 6.9 or 7.0 were exposed to the full chained attack. Sites on 6.8 were only affected by the first of the two flaws, which is still worth patching, but not the same level of exposure. WordPress fixed it in 6.8.6, 6.9.5, and 7.0.2, depending on which version branch a site was running. Versions before 6.8 are not affected.

What We’re Doing About It at NgageContent

As soon as we found out about this update, our development team got to work. We audited every retainer and web maintenance client’s WordPress installation, checked it against the affected version range, and we’re rolling out updates.

If your site is under one of our maintenance or retainer plans, you don’t need to do anything. We’re on it. We treat security updates like this one as a top priority. We won’t wait around until your next scheduled maintenance to do this update.

What If You’re Not on a Website Support Plan?

If we don’t currently manage your WordPress site’s maintenance, we’d still encourage you to check your version. You can find it in your WordPress dashboard under Updates.

If you’re running an older version and aren’t sure whether you’re affected or how to update safely, reach out to us. We’re happy to take a look. If you do need an update, it’s usually a quick fix and not a full-fledged project.

Why Ongoing WordPress Maintenance Matters

This is the exact situation that ongoing site maintenance is built for. Vulnerabilities can surface at any time, and the gap between them popping up and being exploited is extremely small.

That’s why we treat website maintenance as an ongoing responsibility. Staying ahead of issues like this is a core part of what we do for our clients every day.

If you have questions about this update or want to talk about getting your site on a maintenance plan, we’re here to help.