Critical WordPress Vulnerability Under Active Attack

A critical WordPress vulnerability is being actively exploited to take over websites, and if you run a WordPress site it needs your attention this week. The flaw, tracked as CVE-2026-60137, has been added to the US Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalogue, which means attacks are already happening in the wild rather than being a theoretical risk.

WordPress powers a very large share of UK small business websites, so this is worth a couple of minutes of your time even if you are not especially technical.

What the flaw actually is

In plain terms, a part of WordPress core does not properly clean a piece of data (the author__not_in parameter) before using it in a database query. That opens the door to SQL injection, where an attacker feeds in specially crafted input to trick the site’s database into doing something it should not.

On its own that is serious enough. The bigger problem is that this bug can be chained with a second WordPress flaw (CVE-2026-63030) to achieve what is known as unauthenticated remote code execution. In everyday language, an attacker can run their own code on a default WordPress site without needing a username or password. That is about as bad as web vulnerabilities get, because it can lead to a fully hijacked site, defacement, data theft, or your site being used to attack others.

Who is affected

The vulnerability affects WordPress core versions 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2. It is rated critical. If your site runs an older release in any of those branches, treat it as at risk until it is updated.

Why this matters to your business

Your website is often the first thing a customer sees and, increasingly, where they contact you or buy from you. A compromised site can be defaced, quietly loaded with malware that infects your visitors, used to send spam, or have its customer data stolen. Beyond the clean-up cost there is the reputational damage of a “this site may be hacked” warning appearing next to your name in search results, and the possible data protection implications if customer information is exposed.

Because this particular attack needs no login, it is the kind of flaw that automated tools scan the internet for and exploit at scale. You do not need to be a specific target to be caught up in it.

What you should do now

  1. Check your WordPress version. Log in to your admin dashboard and look at the version shown at the bottom of the screen, or ask whoever manages your site.
  2. Update WordPress core immediately. Upgrade to 6.8.6, 6.9.5 or 7.0.2 (or later) depending on your branch. If you have automatic updates enabled you may already be protected, but confirm it rather than assume.
  3. Update your plugins and themes too. The flaw is triggered through untrusted input, and out-of-date plugins are a common route in. Bring everything up to date.
  4. Take a backup first. Before any major update, make sure you have a recent, working backup stored separately, so you can roll back if something breaks.
  5. Check for signs of compromise. If your site ran a vulnerable version while exposed, look for unfamiliar admin users, unexpected files or content changes, and consider a security scan.
  6. Put ongoing protection in place. A web application firewall, reputable managed hosting and a routine patching process turn this from a scramble into a non-event next time.

How System Force IT can help

Keeping WordPress and its plugins patched is exactly the sort of routine, easily-forgotten task that turns into an emergency when a flaw like this appears. At System Force IT we manage updates, backups, monitoring and IT security for businesses across Gloucestershire and the wider UK as a single governed service, so your website and the systems behind it stay protected without you having to track every advisory. If you are not sure whether your site is affected, or you would simply like someone to keep an eye on it, talk to our team on 01452 701355 or get in touch.

Stay one step ahead of the threats

Get our free weekly IT and cyber security briefing for UK businesses. The same threat and policy round-up we send our own clients, straight to your inbox. No spam, unsubscribe any time.

Get the free weekly briefing →

Table of Contents

Would you like to know how we can help?

Get in touch

Name