HawerGroup

Blog · Website security · 9 October 2026 · 2 min read

Three vulnerabilities in WordPress itself, exploited in attacks. What a site owner must do

In July and September 2026 CISA added three vulnerabilities in WordPress core to its catalogue of actively exploited ones. That's rare: usually plugins are the problem. A 15-minute checklist.

When we talk about WordPress break-ins, an old plugin or a weak password is almost always to blame. This time is different. In the last three months the US agency CISA added three vulnerabilities in WordPress core itself to its catalogue of actively exploited vulnerabilities (KEV).

What made the list

  • 21 July 2026: CVE-2026-60137 and CVE-2026-63030. The first is SQL injection when a plugin or theme passes unchecked input to WordPress. The second lets an attacker get around that. Chained together they let an unauthenticated attacker run their own code on the server, which means taking over the site completely.
  • 25 September 2026: CVE-2026-87902. A flaw in page-template resolution lets an unauthenticated attacker include a chosen .php file from outside the theme directory.

"Actively exploited" means this isn't lab theory. There are confirmed attacks.

Why it matters for small businesses

A hacked company website is rarely the target in itself. It's used to send spam, redirect visitors to scams or show them fake CAPTCHA checks that install malware (we wrote about this in our ClickFix post). Your customers get attacked from your domain, and Google may flag the site as dangerous.

The 15-minute checklist

  1. Log in to WordPress → Dashboard → Updates. If you see "A new version of WordPress is available", update right away. Take a backup first; most hosts do it in one click.
  2. Check that automatic security updates are on. The same page shows whether WordPress updates itself. If someone switched it off, switch it back on.
  3. Update all plugins and themes. The first July flaw needs a plugin or theme that passes data unchecked, and there are many of those.
  4. Delete plugins and themes you don't use. A deactivated plugin still sits on the server.
  5. Review the user list. An unknown account with the Administrator role is a sign of a break-in.
  6. Check the site from the outside. Our free scanner shows, among other things, whether the WordPress version is publicly visible and whether .env or .git files are exposed.

If the site does "strange things"

Redirects to unknown sites, new pages full of ads, a Google warning in search results: an update alone won't fix that. Restore a clean backup from before the infection, change every password (WordPress, FTP, database, hosting), and only then update.

In short

  • Three vulnerabilities in WordPress core have been exploited in attacks since July and September 2026.
  • Backup → core update → plugins and themes → delete what you don't use.
  • Automatic security updates must be on.

Sources: CISA Known Exploited Vulnerabilities Catalog (entries of 21 Jul 2026 and 25 Sep 2026), current list in our Security Radar.