Skip to content
A cracked steel vault door with a red warning light ajar, revealing a damaged WordPress logo and scattered server cables, symbolising a critical security breach.

A Major WordPress Security Update Is Out—Who Needs to Act?

Avidni Editorial Team / Care5 min read.

WordPress 7.0.2 addresses critical security flaws with forced auto-updates, but not every site is automatically protected. Kenyan and East African businesses must verify their status and act to secure their sites.

A WordPress site running an unpatched version is now a visible target. On 17 July 2026, WordPress issued version 7.0.2 to address two major security flaws: one critical, one high-severity. The update triggered emergency action from both WordPress and Cloudflare, including forced auto-updates and new Web Application Firewall (WAF) rules. Yet, not every site is automatically protected. Kenyan and East African businesses relying on WordPress must check their update status or risk exposure to attacks that are already being targeted in the wild.

The scale of WordPress in the region: powering everything from newsrooms to online shops and government portals: means even a single unpatched vulnerability can have outsized consequences. The forced update mechanism is a first-line defence, but operational realities mean some sites will not update automatically or may remain partially exposed. This article sets out which WordPress versions are affected, what the vulnerabilities mean in operational terms, and the concrete actions needed to secure business-critical sites.

The urgency is not theoretical. Cloudflare, one of the world’s largest security providers, deployed emergency WAF rules within hours of the WordPress announcement. Their independent advisory confirms active attempts to exploit these flaws. For Kenyan and East African founders, operators, and technical leads, the decision is not whether to update, but how to verify protection and close any remaining gaps.

What Is in the WordPress 7.0.2 Security Update?

WordPress 7.0.2 addresses two vulnerabilities with significant impact:

Both vulnerabilities were considered severe enough to trigger coordinated emergency action by both WordPress and Cloudflare. The official release and independent advisories confirm that exploitation attempts are already underway.

Which WordPress Versions Are Affected?

Not every WordPress site is at risk, but many are. The version-specific breakdown is:

Backported security fixes are available for WordPress 6.8 (as 6.8.6), 6.9 (as 6.9.5), and for sites on the 7.1 beta channel (7.1 Beta 2). Any site running 7.0.2, 6.9.5, 6.8.6, or 7.1 Beta 2 is considered patched against these vulnerabilities.

How Is the Update Being Deployed?

Due to the severity of these vulnerabilities, WordPress has enabled forced auto-updates for affected versions. This is designed to patch as many sites as possible in the shortest time. However, auto-updates are not universal. Some sites: due to custom configurations, disabled auto-updates, or hosting restrictions: may not receive the update automatically.

WordPress’ own advisory instructs all site operators to check their Dashboard for update status or download the new version directly if needed. Relying solely on auto-update is not sufficient for business-critical sites.

What Immediate Actions Should Kenyan and East African Businesses Take?

  1. Log into your WordPress admin Dashboard. Check the site’s current version (found in the bottom right of the Dashboard or under ‘Updates’).
  2. If your site is running 7.0.2, 6.9.5, 6.8.6, or 7.1 Beta 2, no further action is required for these vulnerabilities.
  3. If your version is lower than these, update immediately: either via the Dashboard’s ‘Update Now’ button or by downloading the new release from the official [WordPress release page](https://wordpress.org/news/2026/07/wordpress-7-0-2-release/).
  4. If your site is managed by a hosting provider or third party, request written confirmation that the update has been applied.
  5. If you use Cloudflare, verify that the emergency WAF rules (see their [advisory](https://blog.cloudflare.com/wordpress-vulnerabilities/)) are active for your domain. This provides temporary mitigation but is not a substitute for updating.
  6. After updating, test your site’s core functions and key plugins for compatibility. If issues arise, consult your developer or support provider.

For organisations with multiple WordPress sites, maintain a central log of update status and responsible parties. This is essential for compliance and audit readiness.

Why Is This Update Urgent?

The combination of forced updates and emergency WAF rules is rare and signals real-world exploitation risk. Cloudflare’s independent confirmation of attempted attacks underscores the urgency. While WAF rules can block many known attack patterns, they cannot guarantee protection against new or modified exploits. Only updating WordPress itself addresses the underlying code flaws.

For Kenyan and East African businesses, the reputational and operational consequences of a compromise: defacement, data breach, or loss of service: are often far greater than the cost of timely updates. Regulatory obligations may also require prompt remediation.

Limits, Exceptions, and Unknowns

If your site is on a version prior to 6.8, these specific vulnerabilities do not apply, but you may still be at risk from other unpatched issues. Regular update checks and security reviews remain essential.


ctartrwrt

Build the website or system your next stage needs.

Strategy, Delivery and Ownership in one accountable process.

Bring the brief, the challenge or simply the outcome you need. Avidni will shape it into a clear delivery plan for a business website, e-commerce store, client portal or automated workflow. You will know what is being built, who owns each decision and what happens after launch, with ongoing care available where it adds real value.

Start a Project