WordPress security updates are released throughout the year to patch vulnerabilities in core, themes, and plugins. Missing even one critical update can leave your site exposed to automated attacks that exploit known flaws within hours of public disclosure. This tracker covers every significant WordPress security update in 2026, updated monthly, so you always know what to patch and when.
Why Tracking WordPress Security Updates Matters
When a vulnerability is publicly disclosed and patched, attackers immediately scan for sites still running the old version. The patch itself becomes a roadmap for the exploit. Sites that delay updates by even a few days sit in a window where the vulnerability is known, the fix is available, and bots are actively hunting for unpatched targets.
For a deeper look at how these vulnerabilities are exploited, read our guide on the 10 WordPress security mistakes that get sites hacked.
July 2026
WordPress 7.0.2 Security and Maintenance Release (July 15, 2026)
WordPress 7.0.2 addresses 3 security fixes and 12 bug fixes. The security fixes patch a stored cross-site scripting (XSS) vulnerability in the block editor, a privilege escalation issue in the REST API user endpoint, and a path traversal vulnerability in the media uploader. All three are rated high severity.
Action required: Update immediately. If you're on managed hosting, verify auto-updates applied successfully. If you manage updates manually, test in staging first, then push to production.
Critical Plugin Vulnerabilities — July 2026
Contact Form 7 (v6.1.2): Patched an authenticated SQL injection vulnerability. Update immediately if you use this plugin — it's installed on over 5 million sites.
WooCommerce (v9.4.1): Fixed a payment gateway data exposure issue that could leak partial customer payment information in certain checkout configurations. Update and audit your checkout flow.
Yoast SEO (v24.3): Patched a cross-site request forgery (CSRF) vulnerability in the sitemap settings. Low severity but update as part of your regular cycle.
June 2026
WordPress 7.0.1 Security and Maintenance Release (June 10, 2026)
WordPress 7.0.1 addressed 4 security vulnerabilities and 15 bug fixes. Key patches included a critical authentication bypass in XML-RPC, a moderate XSS vulnerability in the comment moderation panel, and two information disclosure issues in the REST API. For a complete breakdown, read our detailed guide on .
May 2026
WordPress 7.0 Major Release (May 20, 2026)
WordPress 7.0 was a major release introducing significant architectural changes. While not primarily a security release, it included updated authentication flows and improved nonce handling. We covered the security implications in detail in our .
Critical Plugin Vulnerabilities — May 2026
Elementor (v3.28.1): Patched a critical remote code execution vulnerability affecting the template import feature. Any site running Elementor should have updated immediately.
UpdraftPlus (v1.24.8): Fixed an authentication bypass that could allow unauthorized access to backup downloads. High severity — backups can contain database credentials.
How to Stay Protected Between Updates
Updates alone aren't enough. Between patches, your site needs layered protection:
- Web Application Firewall filtering known attack patterns before they reach WordPress — see our for the right setup
- File integrity monitoring alerting you when core files are modified unexpectedly
- Automated off-site backups so you can roll back if an update breaks something
- Login protection with two-factor authentication and attempt limiting
If managing updates, security monitoring, and backups across your sites is becoming a burden, our handle all of this on a monthly basis.
Frequently Asked Questions
How quickly should I apply WordPress security updates?
Security updates should be applied as soon as possible — ideally within 24 hours of release. Known vulnerabilities are actively exploited by automated bots scanning for unpatched sites. Test major updates in staging first, but don't delay security patches.
Do I need to update plugins even if I'm not using them?
Deactivated plugins still contain exploitable code. If you're not using a plugin, delete it entirely rather than leaving it deactivated. If you are using it, keep it updated on the same schedule as WordPress core.
What happens if an update breaks my site?
This is why backups and staging environments matter. Always take a backup before updating, test in staging for major version changes, and have a rollback plan. If an update breaks functionality, restore from backup and report the conflict to the plugin developer.
How do I know if my site has already been compromised by a known vulnerability?
Check our guide on the . Common indicators include unexpected redirects, unknown admin users, and Google Search Console security warnings.
This tracker is updated on the 1st of each month. Bookmark this page and check back monthly, or contact us for a free security scan if you're not sure whether your site is current.




