← All articles Security

WordPress Core Flaw Scores 9.2: Patch Your Site Now

A flaw confirmed in WordPress core, in the software itself, means an attacker can read files from your server or execute malicious code without ever

Published Jason Boyd

A flaw confirmed in WordPress core, in the software itself, means an attacker can read files from your server or execute malicious code without ever needing a username or password. No brute-force attempt, no stolen credentials, no login page involved at all. If your site is running an unpatched version of WordPress, it is exposed right now.

The vulnerability carries a CVSS score of 9.2 out of 10. That scoring system runs from zero to ten, and anything above nine sits in the category reserved for the most severe flaws a piece of software can contain. At that level, attackers can access configuration files that contain your database credentials, read sensitive data stored on the server, or run code that gives them persistent control over your hosting environment. One compromised site on a shared hosting account can become a route into every other site in that account.

What a 9.2 Score Means When Translated Into Business Consequences

Technical severity scores are written for security researchers. Business owners need a different translation.

File read access means an attacker can retrieve your wp-config.php file, which holds your database name, username, and password in plain text. With those credentials, the attacker has direct access to every record in your database: customer names, email addresses, order history, any personal data your site collects. If you operate under UK GDPR, a breach of that kind triggers a mandatory 72-hour reporting window to the ICO, and failing to report — or being unable to demonstrate you took reasonable steps to secure the site — carries financial penalties.

Code execution goes further. An attacker who can run arbitrary code on your server can install backdoors, redirect your visitors to malicious sites, harvest payment data in transit, or enlist your server in attacks on other targets. Your domain gets flagged by Google, your hosting account gets suspended, and customers who land on a warning page do not come back. Some businesses recover from reputational damage at that scale; others find that a single incident, covered in trade press or flagged in a Google search of their company name, permanently changes how prospects perceive them.

The patch already exists. WordPress 7.1.2 contains the fix, and backports have been issued covering every version of WordPress back to 4.7, meaning the update is available regardless of which version you are currently running. There is no technical barrier to applying it. The only question is whether it has been applied to your site.

The Version Number on Your Dashboard Is Not Proof the Patch Has Been Applied

Many businesses rely on automatic updates and assume the job is done. Automatic updates are a good default, but they do not always complete successfully. A hosting environment with certain configurations, a plugin conflict, or a failed update process can leave your site on an outdated version whilst showing no obvious error, and the only reliable confirmation is checking the version number in your WordPress dashboard and verifying it reads 7.1.2 or higher.

If you have a web team or a developer managing your site, ask them directly: has WordPress 7.1.2 been applied, and do you have confirmation it completed without errors? That is a one-sentence question. If the answer is anything other than a clear yes with evidence, treat the site as unpatched until you know otherwise.

For sites running WooCommerce, the stakes are higher. WooCommerce stores hold order records, customer accounts, and in some configurations, stored payment tokens. A database exposed through this vulnerability gives an attacker access to every order record in your WooCommerce database, including billing addresses, phone numbers, and purchase history. If your store uses a hosted payment gateway and no card data touches your server, that specific exposure is limited — but the customer data is still there, and it is still personal data under UK GDPR.

WooCommerce stores that use the built-in WooCommerce > Settings > Accounts and Privacy configuration to allow guest checkout collect customer data without account creation. That data sits in your database whether or not a customer account exists, so a breach exposes it regardless. A vulnerability in WordPress core affects everything built on top of it: plugins, themes, and WooCommerce extensions all inherit the exposure of the platform they run on. Patching the core is the foundation everything else depends on.

One consequence that rarely gets discussed in these situations is cyber insurance. Many business insurance policies that include cyber cover contain clauses requiring the policyholder to apply security patches within a defined window, often 30 days of release. Running a site on a known, unpatched vulnerability after a fix has been publicly issued can void a claim. If your site is breached and an insurer’s investigation shows the patch was available and not applied, the financial protection you were counting on will not be there.


If you are not certain whether WordPress 7.1.2 has been applied to your site, I can check and apply it for you. Given that this vulnerability allows unauthenticated file access and code execution, every day an unpatched site is live is a day it can be exploited without warning. Contact me at The WordPress Guy to book a security update check. I will confirm your current version, apply the patch if it has not been applied, and run a post-update verification so you have documented confirmation the fix is in place.

Related articles

All articles →

Security issues need permanent fixes, not surface-level patches. This is exactly the work I specialise in.

View security services →
Jason Boyd

Jason Boyd

Specialist WordPress Engineer · Former W3C Invited Expert · 20+ years

I fix the WordPress problems other developers walk away from. Backed by a 1st Class degree in Computer Science, an MSc in Cybersecurity, and over 20 years of specialist WordPress work, I diagnose issues at their root cause and resolve them permanently, for businesses that cannot afford guesswork or repeat failures.

Need hands-on help?

If this article describes your situation, I can diagnose the specifics and fix it properly. Send your brief and I'll respond the same working day.