Home / Insights / Article

// Darksteel Insights · 2026-07-24

New WordPress Vulnerability: What SMBs Need to Know

A newly exploited WordPress vulnerability is now being used in real-world attacks, and small and mid-sized businesses are at risk.

The short version
  • A newly exploited vulnerability in WordPress (CVE-2026-63030) is currently being used in attacks.
  • SMBs using WordPress should update immediately to protect their site.
  • Scan your site for unauthorized changes to check if it has been compromised.
  • Professional security services can help ensure your site is patched and secure.

What is this WordPress vulnerability?

CVE-2026-63030 is a flaw in the core of WordPress, the widely used website platform. It involves a conflict in how WordPress processes certain commands, which attackers can exploit to access or manipulate your site.

Because this flaw is in WordPress Core, it affects all sites running an unpatched version of the software. That means if your site hasn’t been updated recently, it could be at risk.

This vulnerability has already been added to CISA’s list of known exploited vulnerabilities, which means it’s being actively used in attacks.

Why should SMBs care?

If your business website runs on WordPress, and it’s not updated to the latest version, it could be exploited. Attackers could gain access to your site, change content, or install harmful software.

A compromised website can damage your business’s reputation and customer trust. If attackers use your site to spread malware or phishing links, you could face legal or financial consequences.

Even if you don’t notice anything wrong, attackers could be using your site without your knowledge. That’s why it’s important to act quickly and ensure your site is patched.

What should you do this week?

First, check the version of WordPress your site is running. If it’s not updated to the latest version as of July 2026, apply the update immediately.

If you use a managed WordPress host or a web developer, reach out to them and confirm that the latest security updates have been applied. Don’t assume they’ve done it automatically.

Next, scan your site for any unusual changes. Look for unfamiliar plugins, unexpected files, or changes in how your site behaves.

If you’re unsure about any of these steps, consider hiring a professional to perform a security scan and confirm your site is secure.

How can I tell if my site was already hit?

If your site was running an unpatched version of WordPress and you’ve noticed unusual login attempts or traffic patterns, it’s possible your site has been compromised.

Signs of a breach include unexpected changes to your site’s content, strange redirects, or performance issues. You might also see unfamiliar plugins or files in your dashboard.

The best way to be certain is to run a security scan or bring in a professional to check for unauthorized changes or malicious code.

If you suspect a breach, back up your site and disconnect it from the internet until a security expert can investigate.

Why is this vulnerability being exploited so quickly?

This vulnerability is being used in attacks because it’s in a core part of WordPress, which is used by many websites.

Attackers can use automated tools to scan for and exploit vulnerable sites quickly. That means the longer your site remains unpatched, the higher the risk.

Because of this, it’s critical for SMBs to act fast and apply the patch as soon as possible to avoid being targeted.

Not sure whether your environment is exposed? That is exactly what our Vulnerability Management service is built to surface. Talk to us.

Frequently asked questions

What is a 'known exploited vulnerability'?
A known exploited vulnerability is a security flaw that has been publicly disclosed and is currently being used by attackers in real-world attacks. CISA tracks these and adds them to a list called the Known Exploited Vulnerabilities (KEV) catalog.
Can I fix this myself?
If you’re comfortable updating your WordPress site and checking for suspicious changes, you can apply the patch yourself. However, if you’re unsure or if your site is already compromised, it’s best to get help from a professional.
How do I know if my site is using a vulnerable version?
Log into your WordPress dashboard and check the version number under 'Help' in the bottom left. If it’s older than the patched version released in July 2026, you’re at risk.
What if I use a managed WordPress host?
Contact your host and ask if they’ve applied the latest security updates. Some hosts automatically update sites, but you should confirm and ask for proof that the patch is applied.
What if I'm not sure if my site is compromised?
Look for unexpected changes in your site's content, performance, or traffic patterns. If you're still unsure, have a professional security firm scan your site for signs of compromise.
What's the best way to protect my site from future attacks?
Keep all software up to date, use strong passwords, limit login attempts, and monitor your site regularly for changes. A managed security service can also help automate these tasks and respond to threats quickly.

Source (public domain): CISA