(844) 523-1957
🇪🇸 Español

WordPress Security: What the Latest Attack Wave Means

Web ServicesBy J.M. Field5 min read

If your business website runs on WordPress, a recent security story is worth two minutes of your attention. In July 2026, researchers reported that hackers were actively attacking WordPress sites through flaws in the core software, and millions of sites were exposed. The part most headlines skipped is the good news: protecting your site is straightforward once you understand what actually went wrong.

What Actually Happened

In July 2026, security researchers reported that attackers were exploiting two critical flaws in WordPress core, the base software that runs the platform. Firms that watch for these threats, including Patchstack, Hexastrike, and WatchTowr, confirmed the attacks were happening in the wild, not just in theory. The underlying bug chain was nicknamed WP2Shell, and it was first discovered by researcher Adam Kues of Searchlight Cyber.

Tens of millions of websites were considered at risk. That number sounds frightening, but it needs context, and the context is where the real lesson lives.

The Detail Most Headlines Skip

These flaws were already fixed before the attacks began. WordPress had released a patch and even pushed forced updates to help site owners stay protected. The sites getting hit are the ones that never installed that update.

This is the pattern behind almost every WordPress breach. When a fix is published, attackers study it, build tools to target sites that have not applied it yet, and then scan the web for stragglers. Managed hosts such as WordPress.com, Pressable, WPVIP, and WP.cloud patched their customers right away, and the sites on those hosts stayed protected. The problem was never WordPress itself. The problem was sites left un-updated.

Is My Site Affected

The flaws affect WordPress core versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. It is worth repeating that this is a core vulnerability, not a plugin issue, so what matters is the version of WordPress your site runs.

Checking your version takes a minute. Log into your WordPress admin dashboard and look at the bottom right corner of the screen, where the version number is shown. If you are not sure how, ask whoever maintains your site. If your site is on a current, fully updated version of WordPress, you are already protected from this particular attack.

To show the scale, an estimated 400 million sites ran an affected version at some point. Security consultant Daniel Card estimated that fewer than 15 percent were actually vulnerable, which still leaves roughly 90 million sites at real risk. Cloudflare also began blocking exploit attempts to slow the attackers down.

Why This Keeps Happening

According to W3Techs, WordPress powers more than 40 percent of all websites. That popularity is a strength, but it also makes WordPress the biggest target on the web. Automated tools scan millions of WordPress sites every day, looking for a known weakness to walk through.

WordPress is a capable platform when someone keeps it current. The trouble is that many sites are built once and then left alone for months or years. Plugins go stale, the core version falls behind, and the risk quietly builds up in the background. None of that is a WordPress flaw. It is a maintenance gap, and a maintenance gap is fixable.

Path 1: Keep Your WordPress Site Properly Maintained

If your WordPress site fits your business, you do not need to replace it. You need someone keeping it in good shape. Our team handles ongoing website maintenance that keeps a WordPress site updated, patched, backed up, monitored, and hardened against attacks. When that maintenance is in place, an attack wave like this one simply passes your site by, the same way it passed by the sites on those managed hosts.

This is the most direct answer to the WordPress security question. Most sites that get breached were not unlucky. They were unmaintained.

Path 2: Build on a Smaller Target

Some businesses would rather not manage a database and a stack of plugins at all. For them, J.M. Field also builds fast websites on Astro, the same framework that runs jmfield.com. An Astro build has no live WordPress database and no plugin layer for these attacks to reach, which removes the exact surface this kind of exploit depends on. It also loads faster for your visitors. If your site is mostly there to inform and convert, a modern Astro build can give you strong security with very little to maintain.

Which Path Is Right for You

There is no single right answer, and we will not pretend there is. If your WordPress site works well and your business depends on its features, like a store, a membership area, or custom forms, keeping it professionally maintained is usually the smart move. If your site is mainly informational and you care most about speed and security, a static rebuild may serve you better for years. The right call depends on your site, your budget, and where your business is headed.

That is exactly the kind of question we are happy to talk through with you, with no pressure either way.

J.M. Field has been a trusted Fort Lauderdale partner for over 30 years, and our Web Services team helps businesses keep their websites secure, fast, and up to date. If you are not sure whether your site is safe, or which path fits your business, we will review your current site and give you honest advice at no cost. Book a free web services consultation, or call us at (844) 523-1957.

Get a Free Web Services Review →
WordPress Security

Questions About the WordPress Attack Wave

How do I check my WordPress version?
Log into your WordPress admin dashboard and look at the bottom right corner of the screen, where the version number is displayed. You can also ask your web developer or hosting provider to confirm it for you. If your site is on a current, fully updated version, you are protected from this attack.
Is WordPress safe to use?
Yes, when it is actively maintained. Because WordPress powers more than 40 percent of all websites, it is targeted often, but timely updates close the door on these attacks. The sites that get breached are almost always the ones that were left un-updated, not sites that were kept current.
What WordPress versions are affected by this issue?
The affected versions are WordPress core 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. This is a core vulnerability, not a plugin flaw, so the fix is updating WordPress core itself to a current, patched version.
Should I move off WordPress?
Not necessarily. If your site relies on plugins, e-commerce, or membership features, keeping WordPress professionally maintained is usually the right call. If your site is mostly informational and you want lower maintenance and a smaller attack surface, a static Astro build can be a strong alternative. It depends on your site.

Ready to Talk?

Whatever operational challenge you are reading about, we have probably solved it. Let us talk.

Get a Quote →