WordPress Releases Emergency Security Update After Discovering Website Visitors Could Become Administrators By Thinking About It Hard Enough
SAN FRANCISCO — The WordPress security team released version 7.0.2 Friday after researchers discovered two severe vulnerabilities allowing attackers to remotely execute code, access databases, alter websites, and briefly enjoy better administrative control than the site’s actual owner.
Officials described the update as “critical,” which in WordPress terminology means users should stop whatever they are doing, update immediately, clear every cache layer known to man, and then spend the afternoon determining which essential plugin has exploded.
Due to the severity of the vulnerabilities, WordPress activated forced automatic updates, a reassuring feature in which the software repairs itself in the middle of the night while site owners sleep peacefully, unaware that their homepage will be replaced by a white screen reading:
“There has been a critical error on this website.”
The flaws reportedly involved SQL injection, REST API confusion, and remote code execution—three phrases carefully chosen to ensure small-business owners understand absolutely nothing except that someone in Belarus may now control the roofing company’s About Us page.
Security experts advised administrators to update WordPress core immediately, then update 37 plugins, six themes, PHP, MySQL, Apache, the server operating system, Cloudflare, their DNS records, their passwords, their security salts, and possibly their smoke detectors.
WordPress emphasized that versions prior to 6.8 are not affected, mainly because hackers opened them years ago, looked around, and said, “Oh, this place has already been through enough.”
The update was made possible by dozens of researchers, contributors, hosting companies, and engineers working together across the globe to close the vulnerabilities before the average WordPress administrator could finish clicking “Remind Me Later” on the dashboard notice.
At press time, one site owner reported that 7.0.2 installed successfully but remained concerned after Wordfence sent an email titled:
“Your Site Is Probably Fine, But Open This Immediately Or You Will Never Forgive Yourself.”
