
Week in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logs
July 19, 2026
CompTIA Security+ Exam Preparation Guide
July 20, 2026An unauthenticated attack on WordPress sites can potentially allow an attacker to run arbitrary code. This vulnerability lies in the core of WordPress itself, meaning even a fresh installation with no plugins is susceptible to exploitation. The issue has been found to affect sites running versions 6.9 and 7.0 of the platform until a patch is released.
According to recent updates, the two security flaws have been assigned CVE IDs and their underlying mechanism has been publicly disclosed. Furthermore, a persistent object cache condition has been identified as a potential issue. A working proof-of-concept for this vulnerability has also been made available, highlighting the severity of the situation.
WordPress administrators are urged to take immediate action to secure their sites, pending the release of a patch. It is crucial to stay vigilant and apply security updates promptly to prevent potential exploitation of this critical vulnerability.





