Wordpress Security Update
Critical WordPress Security Alert: Update Your Site Immediately
This past week, security researchers uncovered two serious vulnerabilities affecting WordPress core versions 6.8 to 7.0.1.
Read that again… that’s the WordPress core!!!
This isn’t a plugin issue. It isn’t a theme vulnerability. These flaws exist in WordPress itself.
When chained together, the vulnerabilities allow an individual, group, or automated bot, to take complete control of an affected website. No login credentials are required, and remarkably, the attack can succeed on a site running zero plugins.
In other words, it doesn’t matter how beautifully your website has been designed, how selective you’ve been with plugins, or how well you’ve maintained your theme. If you’re running an affected version of WordPress, your website could be one exploit away from rock bottom… and unfortunately, the exploit has already been made public.
Cybercriminals are already actively scanning the internet for vulnerable WordPress installations, so this isn’t something to put on next week’s to-do list.
What You Need to Do
If your website is on a Volta Creative Care Plan
You don’t need to do a thing.
We’ve already rolled out the latest WordPress core updates across all managed websites. Keeping your site secure, monitored, and up to date is exactly why our Care Plans exist. When critical vulnerabilities like this appear, we act immediately so you don’t have to.
If your website isn’t on a Care Plan
Please log in to your WordPress dashboard today.
Check your current WordPress version
Update to the latest available release immediately*
Don’t delay – the update only takes a couple of minutes, but the consequences of ignoring it could be far more costly
A compromised website can lead to malware being installed, customer data being exposed, spam being sent from your domain, search engine blacklisting, or even complete loss of your website.
If you’re unsure whether your site has been updated, or you’d like us to take care of ongoing maintenance and security for you, get in touch with the Volta Creative team. We’d much rather spend a short time updating your website than hours helping recover it after an attack.
* Note: if your site, core and plug-ins haven’t been updated regularly, there is always the chance that updates may cause a conflict – in most cases we can correct any issues.
