← All articles Security

WordPress 7.1: Security Flaw Puts 6.9–7.0.1 Sites at Risk

A major WordPress update lands on 19 August 2026, timed with WordCamp US 2026, and the beta cycle is already revealing exactly why this one deserves your

Published Jason Boyd

A major WordPress update lands on 19 August 2026, timed with WordCamp US 2026, and the beta cycle is already revealing exactly why this one deserves your attention before the release date arrives. If your site is running WordPress anywhere between version 6.9.0 and 7.0.1, you are currently exposed to a security vulnerability for which working exploit scripts are already circulating publicly on repository networks such as GitHub. That is the operational reality right now, before 7.1 even ships.

The update addresses more than 71 issues logged since Beta 1 launched. Some of those fixes are routine; others are not. Beta 2 shipped as part of the WordPress 7.0.2 release and carried security patches specifically targeting the vulnerability that affects versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. Beta 3 followed with targeted fixes: a bug causing long animated GIF uploads to hang, a correction to how images rotated using EXIF metadata are processed, and a fix for a Safari-specific issue where uploading a single HEIC image created two entries in the media library. A media library that duplicates uploads or silently corrupts image orientation creates real problems for product pages, editorial content, and any site where images carry commercial weight — which is why none of these are abstract engineering concerns.

The Security Exposure on Sites Running 6.9.0 to 7.0.1

Proof-of-concept exploit scripts for the vulnerability affecting WordPress 6.9.0 through 7.0.1 are already publicly available, which means the barrier to running an attack against an unpatched site is low. No sophisticated actor is required. Anyone with access to those scripts and a list of WordPress versions can target sites at scale.

Business owners sometimes treat WordPress updates as optional maintenance, something to schedule when convenient. Every day a site remains on an affected version, it sits in a pool of known targets, and this vulnerability changes that calculation entirely. An attacker gaining access through a WordPress core vulnerability can take administrative control, inject code, redirect traffic, or extract data. The specific outcome depends on the exploit, but none of them are recoverable without cost.

Update to a patched version now, before 7.1 releases. If your site is on a managed hosting plan, check with your host which version is currently running. If you manage your own installation, log into your WordPress dashboard and check the version displayed at the bottom of the screen. Running 7.0.2 or later means the security patch is in place; running anything between 6.9.0 and 7.0.1 means it is not.

Why Running the Beta on a Live Site Is a Business Liability

WordPress.com’s own guidance is direct on this: beta releases may contain bugs that affect checkout, user registration, or plugin compatibility. These are the categories of breakage that stop revenue and create customer-facing problems, and the period between now and 19 August is not a window to find that out on your production site.

Beta software exists to find bugs before the final release. Running it on a live site means your customers and your revenue become part of the testing process. If a beta introduces a conflict with your payment gateway, your forms plugin, or your membership software, the cost lands on your business, not on the development team that will patch it before the final release.

Install beta releases on a staging environment: a private copy of your site that mirrors production without being accessible to customers. Test your critical workflows there — checkout if you run a WooCommerce store, form submissions, login flows, media uploads. If something breaks on staging, it is a finding. If it breaks on your live site, it is an incident.

The gap between now and 19 August is the right time to do two things. First, confirm your current WordPress version and apply the security patch if you are on an affected version. Second, plan the transition to 7.1 so that when the final release arrives, you are updating a site that has already been tested against the new version, rather than discovering compatibility issues after the fact.

One consequence worth considering that often goes unaddressed: the period immediately after a major WordPress release is when compatibility gaps between core and third-party plugins become visible. Developers release plugin updates to match the new version, but those updates do not always arrive on release day, and a site that updates to 7.1 on 19 August without having tested plugin compatibility first may find that a plugin its business depends on behaves unexpectedly until its own update ships. Planning the update for a few days after the release date, once the plugin ecosystem has caught up, is often the more stable approach.


If your site is running WordPress 6.9.0 through 7.0.1, I can audit your current version, apply the security patch, and build a staged update plan to take you to 7.1 safely before or after the 19 August release. Given that exploit scripts for this vulnerability are already publicly available, the audit is time-sensitive. Contact me at The WordPress Guy to arrange it.

Related articles

All articles →

Security issues need permanent fixes, not surface-level patches. This is exactly the work I specialise in.

View security services →
Jason Boyd

Jason Boyd

Specialist WordPress Engineer · Former W3C Invited Expert · 20+ years

I fix the WordPress problems other developers walk away from. Backed by a 1st Class degree in Computer Science, an MSc in Cybersecurity, and over 20 years of specialist WordPress work, I diagnose issues at their root cause and resolve them permanently — for businesses that cannot afford guesswork or repeat failures.

Need hands-on help?

If this article describes your situation, I can diagnose the specifics and fix it properly. Send your brief and I'll respond the same working day.