Skip to main content
Call us on 02 8999 3311 Free consult
Blog

What's happening with WordPress lately?

WordPress security updates explained: what's driving recent patches, what was fixed, and how to respond safely. Guidance for Australian businesses.

  • Published
  • Updated
What's happening with WordPress lately?

WordPress updates at a glance

We explain why WordPress security updates increased in late 2026, what it means for your site, and how to patch, test, and respond safely.

  • Why updates spiked

    AI-assisted research plus a backlog push has increased security releases and advisory volume.

  • What core patched

    A run of WordPress core security releases fixed issues like XSS, SQL injection, and permission checks.

  • Plugins and themes risk

    Most vulnerability reports still come from extensions, which adds ongoing monitoring and compatibility work.

  • What to do next

    Prioritise exploited fixes, reduce unused plugins, back up first, then verify key workflows after updates.

Developer wearing glasses with code reflection on lenses, representing web development and programming

Why WordPress has had so many security updates lately

More patches do not automatically mean WordPress is getting worse, it usually means more issues are being found and fixed faster.

The recent burst of WordPress security updates is real. As of 9 October 2026, the main drivers are more intensive security research, particularly AI-assisted research, a deliberate effort to clear a backlog of reports, and several serious flaws that attackers started targeting quickly.

WordPress itself has acknowledged the jump in incoming reports and expanded its response. That is a good sign for site owners, but it also means you may need to adjust how you plan maintenance, especially if you currently update monthly.

  • More vulnerabilities are being discovered, including low-impact and duplicate reports.
  • Security releases are shipping faster, sometimes close together.
  • Timely patching matters when attackers probe as soon as advisories are published.
  • Verification matters so updates do not break key workflows.

If you want us to take care of this end to end, our website maintenance and web maintenance services focus on safe updates, backups, and checks. If something is already behaving oddly, start with website troubleshooting.

What was patched in WordPress core

Late September to early October 2026 included three core security releases. They covered a mix of XSS, SQL injection, permission issues, and denial of service fixes.

  • 7.1.1 (17 Sept)

    Included 11 security fixes, covering stored XSS, permission checks, authenticated path traversal, and theme install and preview behaviour.

  • 7.1.2 (22 Sept)

    Addressed one critical flaw in page-template resolution, which could lead to remote code execution under specific configurations.

  • 7.1.3 (6 Oct)

    Added seven security fixes, including comments-related XSS, disclosure of comments on private content, SQL injection during exports, and permission issues.

  • Context matters

    Not every fix has the same real-world impact, some require an existing account, an admin action, or a particular plugin or theme behaviour.

  • Why urgency varies

    Some advisories are followed by probing within hours, others are less likely to be exploited quickly but still should be applied promptly.

Padlock on document representing data security and confidential information protection

19

core fixes

Across three releases in under three weeks

Hand placing customisable block onto modular puzzle structure displayed on computer screen

Why plugins and themes still drive most WordPress risk

Core updates matter, but the bigger maintenance load is often the extension stack, each plugin and theme has its own release cycle and security posture.

Even in a period with several WordPress core security releases, plugins and themes remain the biggest ongoing maintenance issue for most websites. In practice, they create a coordination problem, many separate components to monitor, patch, and test for compatibility.

Patchstack’s 2026 report, covering findings from 2025, recorded 11,334 vulnerabilities in its dataset. Around 91% were in plugins and 9% in themes, with 46% disclosed before a vendor fix was available. These numbers describe reported vulnerabilities, not a direct count of hacked sites.

Two recent examples show how exposure can be broader than expected:

  • Bricksforge (8 Oct), a security fix for Pro Forms file uploads, the vendor noted exposure even when forms have no upload fields.
  • Ninja Forms and WPC Product Bundles (6 Oct), a stored XSS campaign where admin views can trigger malicious actions, including installing backdoors.

If your site is plugin-heavy or uses a page builder, we can help you stabilise it through web maintenance, or take full responsibility through website maintenance. For larger rebuilds or custom features, see website design and development.

What good WordPress maintenance delivers

A calm, repeatable way to handle frequent security releases, without breaking your site or leaving gaps that attackers can exploit.

  • Faster response to exploited issues

    When a vulnerability is actively targeted, we prioritise patching outside a routine monthly window and verify key pages and transactions afterwards.

  • Safer updates, with checks

    We back up before changes, then validate the functions that matter, including forms, checkout, bookings, and page-builder layouts.

  • Reduced plugin sprawl

    We help you remove unused extensions and avoid risky overlaps, which cuts down the number of moving parts you need to monitor and maintain.

  • A clearer compromise response

    If there are signs of a hack, we treat it separately from patching, because closing the entry point does not automatically remove backdoors or rogue accounts.

  • Straight answers about risk

    We explain what an advisory means for your configuration, so you can make sensible decisions without assuming every update is equally urgent.

How we handle WordPress updates

A repeatable process for patching, testing, and reducing risk without disrupting your day to day operations.

  1. Step 01

    Review

    We check core, plugin, and theme advisories and prioritise anything known to be exploited or high impact for your setup.

  2. Step 02

    Backup

    We take a fresh backup before changes so we can roll back if an update causes unexpected issues.

  3. Step 03

    Update

    We apply updates in a sensible order, watching for breaking changes and avoiding unnecessary version jumps where possible.

  4. Step 04

    Verify

    We test the important paths on your site, such as contact forms, purchases, bookings, logins, and any custom integrations.

  5. Step 05

    Harden

    We remove unused plugins, tighten basic settings, and recommend changes that reduce future maintenance load.

  6. Step 06

    Monitor

    We keep an eye on new reports and changes, so urgent patches are not waiting for the next scheduled cycle.

Need help with updates?

Tell us your website address and what you are concerned about, we will suggest a sensible next step.

Contact Us

WordPress security updates FAQs

Not sure what applies to your site? These answers cover common risks and next steps, or see website maintenance, troubleshooting, and hosting.

Have a specific concern about your site?

WordPress and website advice

Practical guidance on maintenance, hosting, performance, SEO, and avoiding common WordPress pitfalls.

  • Website Design & Development

    Primary

    Website Design & Development

    Custom websites built around your business and managed for the long term. Sydney web development agency with ongoing hosting, maintenance, security and support for Australian businesses.
  • Custom Web Applications

    Primary

    Custom Web Applications

    Custom web applications built around your business. We design, develop, host and manage bespoke apps so your team focuses on work, not technology. Sydney-based web development agency supporting Aus...
  • Website Maintenance

    Primary

    Website Maintenance

    Website maintenance handled for you. We manage updates, security, backups and ongoing fixes. Work directly with Sean, your Sydney-based developer.

Want us to manage this?

If WordPress updates are becoming a burden, we can take over maintenance and support, and keep your site stable while security patches keep coming.

Call us
  • Based in Sydney, working Australia-wide
  • Updates, backups, and verification
  • Support for existing WordPress sites

Talk to us

Send an enquiry and include your website address and what you are seeing. If it feels urgent, call us on 02 8999 3311 and we will triage the issue.

Contact Details

  • Phone

    02 8999 3311
  • Email

    [email protected]
  • Location

    Suite 2, 13U/175 Lower Gibbes Street
    Chatswood NSW 2069
  • Business Hours

    Mon - Friday:
    9:00 AM - 5:00 PM
    Sat - Sun:
    Closed

Want a website that works as hard as you do?

Get honest, practical advice on your website, SEO, or next build. No jargon, no lock-in contracts.