WordPress security updates are released throughout the year to patch vulnerabilities in core, themes, and plugins. Missing even one critical update can leave your site exposed to automated attacks that exploit known flaws within hours of public disclosure. This tracker covers every significant WordPress security update in 2026, updated monthly, so you always know what to patch and when.
Why Tracking WordPress Security Updates Matters
When a vulnerability is publicly disclosed and patched, attackers immediately scan for sites still running the old version. The patch itself becomes a roadmap for the exploit. Sites that delay updates by even a few days sit in a window where the vulnerability is known, the fix is available, and bots are actively hunting for unpatched targets.
Book a free, no-obligation strategy call and we'll map out your next move.
For a deeper look at how these vulnerabilities are exploited, read our guide on the 10 WordPress security mistakes that get sites hacked.
July 2026
WordPress 7.0.2 Security and Maintenance Release (July 15, 2026)
WordPress 7.0.2 addresses 3 security fixes and 12 bug fixes. The security fixes patch a stored cross-site scripting (XSS) vulnerability in the block editor, a privilege escalation issue in the REST API user endpoint, and a path traversal vulnerability in the media uploader. All three are rated high severity.
Action required: Update immediately. If you're on managed hosting, verify auto-updates applied successfully. If you manage updates manually, test in staging first, then push to production.
Critical Plugin Vulnerabilities — July 2026
Contact Form 7 (v6.1.2): Patched an authenticated SQL injection vulnerability. Update immediately if you use this plugin — it's installed on over 5 million sites.
WooCommerce (v9.4.1): Fixed a payment gateway data exposure issue that could leak partial customer payment information in certain checkout configurations. Update and audit your checkout flow.
Yoast SEO (v24.3): Patched a cross-site request forgery (CSRF) vulnerability in the sitemap settings. Low severity but update as part of your regular cycle.
June 2026
WordPress 7.0.1 Security and Maintenance Release (June 10, 2026)
WordPress 7.0.1 addressed 4 security vulnerabilities and 15 bug fixes. Key patches included a critical authentication bypass in XML-RPC, a moderate XSS vulnerability in the comment moderation panel, and two information disclosure issues in the REST API. For a complete breakdown, read our detailed guide on WordPress 7.0.1: what's new and what changed.
May 2026
WordPress 7.0 Major Release (May 20, 2026)
WordPress 7.0 was a major release introducing significant architectural changes. While not primarily a security release, it included updated authentication flows and improved nonce handling. We covered the security implications in detail in our WordPress 7.0 security hardening guide.
Critical Plugin Vulnerabilities — May 2026
Elementor (v3.28.1): Patched a critical remote code execution vulnerability affecting the template import feature. Any site running Elementor should have updated immediately.

