A critical vulnerability has been discovered in WordPress that may allow malicious code to be executed on a website without authentication. The vulnerability has been fixed in version 7.0.2.
The vulnerability affects the following versions:
- 6.8.0 to 6.8.5
- 6.9.0 to 6.9.4
- 7.0.0 to 7.0.1
Update WordPress to version 7.0.2 immediately.
The update can be installed using the application installer in the web hosting control panel. See the instructions: Updating a WordPress site using the application installer.
We have blocked the known method of exploiting the vulnerability at the server level. However, this protection does not replace updating WordPress.
More information is available on the website of the National Cyber Security Centre Finland.
