A security update has been released to fix two critical vulnerabilities in WordPress 6.8, 6.9, and 7.0 (CVE-2026-60137 and CVE-2026-63030). Sites hosted on Altis are automatically protected, however we recommend further action.
This corresponds to Altis v25 (WP 6.8), Altis v26 (WP 6.9), Altis v27 (WP 7.0). (Earlier versions are not affected.)
Altis deployed firewall mitigations prior to public disclosure of this vulnerability, and your site is not exploitable. There is no evidence at this time that this vulnerability was known “in the wild” prior to the public disclosure.
While your site is protected by the Altis firewall mitigation, we still strongly recommend upgrading to the latest WordPress version as soon as possible to fix the underlying issue. This can be done by updating the johnpbloch/wordpress dependency on your repository – either using composer update -W altis/cms or using the Dependabot pull request for this dependency.
This mitigation was deployed ahead of the public release of this vulnerability to protect customers early. We’d like to thank the members of the hosting security group for the collaboration on mitigating this issue.
Our Secure by Design approach to the Altis platform mitigated the Remote Code Execution vector present in WordPress core through the read-only executable (W^X) filesystem. This security release was also led by John Blackbourn, WordPress security team lead and Director of WordPress Security at Altis – we’re proud that our investment in WordPress helps to make the web safer.
More information about this vulnerability is available on the WordPress website: https://wordpress.org/news/2026/07/wordpress-7-0-2-release/