(434) 236-9027

Hackers Are Hitting WordPress Sites Right Now. Here Is What It Means for Yours.

A locked padlock on a laptop keyboard, representing the July 2026 WordPress core security attack wave
Bottom line

In July 2026, hackers began mass-exploiting two already-patched flaws in WordPress core (a bug chain nicknamed WP2Shell). The sites getting hit are the ones that never installed the update. If you run WordPress, check your version today: 6.9.0 through 6.9.4 and 7.0.0 to 7.0.1 are the danger zone, and updating is the fix. A hacked site does not just go down, it can get flagged and even deindexed by Google, which can wipe rankings you spent months earning. Two ways I keep client sites safe: lock WordPress down properly, or build on a static site with almost nothing to hack.

If your business runs on WordPress, a security story from this month is worth two minutes of your time. Security researchers reported that attackers are actively exploiting recently patched flaws in WordPress core, and tens of millions of sites were exposed. That sounds scary, but the real lesson is simple and it is good news: staying safe here is mostly about not skipping updates.

What Actually Happened

In July 2026, researchers reported two critical flaws in WordPress core, the base software that runs the platform. This is a core issue, not a plugin problem. The cybersecurity firms Patchstack, Hexastrike, and WatchTowr all warned that hackers were exploiting the flaws in the wild, not just in theory. One of the bugs was found and reported by Adam Kues of Searchlight Cyber, which named the exploit chain WP2Shell.

The Part That Matters

Here is the detail most headlines skip: these flaws were already fixed before the attacks started. WordPress shipped a patch and even enabled forced updates where it could. The sites getting hit are the ones that never applied the update.

This is the pattern behind almost every WordPress breach I have cleaned up. When a fix is published, attackers study it, build tools to target sites that have not patched yet, and scan the web for stragglers. Managed hosts like WordPress.com, Pressable, WPVIP, and WP.cloud patched their customers right away, and those sites stayed safe. The problem was never WordPress itself. It was sites left un-updated.

Check Your Site in Two Minutes

The vulnerable versions are WordPress core 6.9.0 through 6.9.4 and 7.0.0 to 7.0.1. To check yours, log into your WordPress admin dashboard and look at the bottom right corner, where the version number is shown. If you are not sure how, ask whoever maintains your site. If you are on a current, fully updated version, you are already protected from this attack.

To put the scale in perspective: according to WordPress's own usage stats, more than 400 million sites ran an affected version at some point. Security consultant Daniel Card estimated that fewer than 15 percent were actually vulnerable, which still leaves around 90 million sites at real risk. Cloudflare stepped in and began blocking exploit attempts to buy site owners time.

Why a Hacked Site Is an SEO Disaster

This is the part that keeps my clients up at night, and it is the reason I care about this as an SEO person and not just a developer. A compromised site rarely just goes offline. More often it quietly starts serving spam pages, redirects, or malware, and Google notices before you do.

When that happens, Google can slap a "This site may be hacked" label under your listing, show a full-screen browser warning to anyone who clicks, or drop your pages from the index entirely. Rankings you spent months or years earning can vanish in days. Cleaning the malware is the easy part. Rebuilding lost trust with Google, and with the customers who saw that warning, takes far longer than the attack ever did. Security is not separate from SEO. A site that is not secure is one bad week away from being invisible.

Path 1: Lock Down Your WordPress

If your WordPress site fits your business, you do not need to replace it. You need someone keeping it in good shape. That means applying core, theme, and plugin updates the day they land, running a firewall and malware scanner like Wordfence, putting Cloudflare in front of the site, keeping daily off-server backups, and trimming plugins down to the ones you actually use. Every plugin is another door, so fewer doors means fewer locks to worry about.

I walk through the full routine in my website security checklist, and the Cloudflare setup guide covers the single highest-leverage 15 minutes you can spend. If you would rather hand it off, this is exactly what ongoing website maintenance is for: someone watching the updates so an attack wave like this one passes your site by.

Path 2: Move to a Site With Nothing to Hack

Some businesses would rather not babysit a database and a stack of plugins at all. For them, I build fast sites on Astro, the same framework this site runs on. A statically generated Astro site has no live WordPress database and no plugin layer for these attacks to reach, which removes the exact surface this kind of exploit depends on. It also loads faster, which your visitors and Google both reward.

This is not theory. My Fancy Pet Salon build, 162 pages and fully bilingual, is static. It has never been hacked, and it never will be through a software vulnerability, because there is no software running on it beyond a web server handing out files. If your site is mostly there to inform and convert, a modern build like that gives you strong security with very little to maintain.

Which Path Is Right for You

There is no single right answer, and I will not pretend there is. If your WordPress site works well and your business leans on its features, like a store, a booking system, or a membership area, keeping it professionally maintained is usually the smart move. If your site is mainly informational and you care most about speed and security, a rebuild on Astro may serve you better for years. It depends on your site, your budget, and where the business is headed.

Bottom line

Update WordPress today if you are on 6.9.0 through 6.9.4 or 7.0.0 to 7.0.1, because the patch is the fix and un-patched sites are the ones getting hit. Remember that a breach is an SEO problem too: a flagged, deindexed site loses the rankings you worked for. Then pick a lasting path, either lock WordPress down with real maintenance, or move to a static Astro build with almost nothing to attack. Not sure which fits? Tell me about your site and I will give you an honest read at no cost.

Mr. Botsworth

Mr. Botsworth

Hey! I'm Mr. Botsworth, Greg's search bot. Ask me about his projects, skills, or services.