Serious vulnerabilities have been discovered in the following WordPress versions:
- 6.8.0–6.8.5
- 6.9.0–6.9.4
- 7.0.0–7.0.1
Exploitation of the vulnerabilities may allow malicious code to be executed on a website without authentication.
Update WordPress to version 7.0.2 immediately.
The update can be installed using the application installer in the web hosting Control Panel. See the instructions: Updating a WordPress site using the application installer.
We have blocked the known method of exploiting the vulnerability at the server level. However, this protection does not replace updating WordPress.
Sites covered by our WordPress Care service have been updated to the latest WordPress version. To leave the technical updates of your WordPress site to us, see our WordPress Care service.
For more information about the vulnerability, see the National Cyber Security Centre Finland’s advisory.
