WordPress has released version 7.0.2, an urgent security update addressing two serious vulnerabilities: a critical facilitated SQL injection issue and a high-severity REST API vulnerability that could allow SQL injection leading to remote code execution.
Because of the severity of these issues, we’re not waiting on our usual update cycle. Starting today, Workhorse is updating all client sites running WordPress 7.0.x to 7.0.2 across our entire managed fleet.
What’s affected
- WordPress 7.0.x — patched by 7.0.2 (today’s priority)
- WordPress 6.9.x — also affected by both issues, patched by 6.9.5 (rolling out immediately after)
- WordPress 6.8.x — affected by one of the two issues, patched by 6.8.6
- Versions prior to 6.8 are not affected
What we’re doing
- Applying the 7.0.2 update across all managed 7.0.x sites first, given the severity
- Following immediately with 6.9.x sites, updating to 6.9.5
- Verifying each site post-update for normal functionality
- Monitoring for any issues introduced by the patch
No action is needed on your end — this is being handled proactively as part of our managed hosting and maintenance service.
For more detail on the vulnerabilities themselves, see WordPress’s official release notes.
Update – July 17 4:15pm
All WordPress sites have been updated to the latest secure version 7.0.2.
Questions? Reach out to your Workhorse account manager or contact us.