{"id":21201,"date":"2026-09-22T08:18:52","date_gmt":"2026-09-22T08:18:52","guid":{"rendered":"https:\/\/www.webhosting.uk.com\/blog\/?p=21201"},"modified":"2026-09-22T08:41:35","modified_gmt":"2026-09-22T08:41:35","slug":"wordpress-security-alert-what-cve-2026-93485-means-for-your-website","status":"publish","type":"post","link":"https:\/\/www.webhosting.uk.com\/blog\/wordpress-security-alert-what-cve-2026-93485-means-for-your-website\/","title":{"rendered":"WordPress Security Alert: What CVE-2026-93485 Means for Your Website"},"content":{"rendered":"<p>If you run a WordPress website, there is a recent security update worth checking.<\/p>\n<p>CVE-2026-93485 is a vulnerability affecting WordPress Core. It has been fixed in WordPress 7.1.1 and patched versions of a number of older WordPress branches.<\/p>\n<p>WordPress released the update on 17 September 2026 and recommends that website owners install the security release immediately.<\/p>\n<h2><strong>What is CVE-2026-93485?<\/strong><\/h2>\n<p>The vulnerability is a type of stored cross-site scripting, usually shortened to stored XSS.<\/p>\n<p>It affects WordPress paragraph formatting and, under the documented conditions, could allow an unauthenticated visitor to insert malicious script into a website. The WordPress security notice says exploitation of this issue is subject to comment approval.<\/p>\n<p>The vulnerability has a CVSS score of 7.1, which is rated High under CVSS 3.1.<\/p>\n<p>In simple terms, cross-site scripting can allow unwanted JavaScript to run in another person&#8217;s browser when they visit an affected page.<\/p>\n<p>That is a good reason to update an affected WordPress installation rather than leave it exposed unnecessarily.<\/p>\n<h2><strong>Is my WordPress website affected?<\/strong><\/h2>\n<p>A large number of WordPress versions received security fixes.<\/p>\n<p>The current WordPress release is 7.1.1, while patched releases were also issued for older branches including 7.0, 6.9, 6.8, 6.7 and several earlier versions.<\/p>\n<p>For example:<\/p>\n<p>&#8211; WordPress 7.0 users can update to 7.0.5<br \/>\n&#8211; WordPress 6.9 users can update to 6.9.8<br \/>\n&#8211; WordPress 6.8 users can update to 6.8.9<br \/>\n&#8211; WordPress 6.7 users can update to 6.7.8<br \/>\n&#8211; WordPress 6.6 users can update to 6.6.8<\/p>\n<p>Security releases were provided for older branches down to WordPress 4.7, although WordPress makes clear that only its latest release is actively supported. WordPress 4.6 and earlier no longer receive security updates.<\/p>\n<p>If you are running a much older WordPress version, it is worth looking beyond this particular vulnerability and reviewing whether the whole installation is still suitable to run.<\/p>\n<h2><strong>What should you do?<\/strong><\/h2>\n<h3><strong>Check whether WordPress has already updated<\/strong><\/h3>\n<p>Have automatic WordPress Core updates switched on? The security update should be installed automatically.<\/p>\n<p>If automatic updates are switched off, you will need to update WordPress manually.<\/p>\n<p>Either way, check your WordPress dashboard and confirm that your site is running a patched version rather than assuming the update has already been applied.<\/p>\n<p>If a manual update is needed, install the appropriate patched release.<\/p>\n<h3><strong>Make sure you have a backup<\/strong><\/h3>\n<p>Before carrying out a manual update, make sure you have a current backup.<\/p>\n<p>More importantly, make sure you know how that backup would be restored. Having backup files somewhere and having a workable recovery process are not quite the same thing.<\/p>\n<h3><strong>Update plugins and themes too<\/strong><\/h3>\n<p>This CVE affects WordPress Core, but WordPress websites also depend on plugins and themes.<\/p>\n<p>Check those regularly for updates and remove anything you no longer use. An abandoned plugin can become an unnecessary security risk.<\/p>\n<h3><strong>Check the website afterwards<\/strong><\/h3>\n<p>Once an update is complete, test the important parts of the site.<\/p>\n<p>For a business website, that might include:<\/p>\n<p>&#8211; contact forms<br \/>\n&#8211; customer logins<br \/>\n&#8211; checkout pages<br \/>\n&#8211; payment integrations<br \/>\n&#8211; important plugins<br \/>\n&#8211; page layouts and navigation<\/p>\n<p>Updating promptly matters, but so does making sure the site still works properly afterwards.<\/p>\n<h2><strong>Why WordPress updates should not be ignored<\/strong><\/h2>\n<p>CVE-2026-93485 was not the only issue addressed by this release.<\/p>\n<p>WordPress 7.1.1 contained 11 security fixes, alongside maintenance fixes for WordPress Core and the Block Editor.<\/p>\n<p>Security updates are a normal part of running a website. WordPress itself, your plugins, themes and server software all change over time.<\/p>\n<p>The important thing is having a sensible process for dealing with them.<\/p>\n<p>For many small websites that means keeping updates enabled, maintaining reliable backups and checking the site regularly.<\/p>\n<p>For larger or more important websites, it may mean taking a more managed approach, where updates, recovery, performance and support form part of the wider hosting decision.<\/p>\n<h2><strong>Is your WordPress hosting still right for your website?<\/strong><\/h2>\n<p>As your website becomes more important to your business, hosting should make it easier to manage rather than becoming another job to worry about.<\/p>\n<p>WHUK provides WordPress hosting backed by real support, with a clear path to more capable hosting as your website grows.<\/p>\n<p>View our WordPress hosting plans to compare the available options, or speak to our team if you are unsure which setup is right for your website.<\/p>\n<p><strong>Suggested sources for publication:<\/strong><br \/>\n&#8211; <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-93485\" rel=\"nofollow\">CVE record<\/a><br \/>\n&#8211; <a href=\"https:\/\/wordpress.org\/news\/2026\/09\/wordpress-7-1-1-maintenance-and-security-release\/\" rel=\"nofollow\">WordPress 7.1.1 release<\/a><br \/>\n&#8211; <a href=\"https:\/\/wordpress.org\/documentation\/wordpress-version\/version-7-1-1\/\" rel=\"nofollow\">WordPress 7.1.1 version notes<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>If you run a WordPress website, there is a recent security update worth checking. CVE-2026-93485 is a vulnerability affecting WordPress Core. It has been fixed in WordPress 7.1.1 and patched&hellip;<\/p>\n<p><a href=\"https:\/\/www.webhosting.uk.com\/blog\/wordpress-security-alert-what-cve-2026-93485-means-for-your-website\/\" class=\"more-link\">Read More<\/a><\/p>\n<div class='heateorSssClear'><\/div><div  class='heateor_sss_sharing_container heateor_sss_horizontal_sharing' data-heateor-sss-href='https:\/\/www.webhosting.uk.com\/blog\/wordpress-security-alert-what-cve-2026-93485-means-for-your-website\/'><div class='heateor_sss_sharing_title' style=\"font-weight:bold\" >Spread the love<\/div><div class=\"heateor_sss_sharing_ul\"><a aria-label=\"Facebook\" class=\"heateor_sss_facebook\" href=\"https:\/\/www.facebook.com\/sharer\/sharer.php?u=https%3A%2F%2Fwww.webhosting.uk.com%2Fblog%2Fwordpress-security-alert-what-cve-2026-93485-means-for-your-website%2F\" title=\"Facebook\" rel=\"nofollow noopener\" target=\"_blank\" style=\"font-size:32px!important;box-shadow:none;display:inline-block;vertical-align:middle\"><span class=\"heateor_sss_svg\" style=\"background-color:#0765FE;width:40px;height:40px;display:inline-block;opacity:1;float:left;font-size:32px;box-shadow:none;display:inline-block;font-size:16px;padding:0 4px;vertical-align:middle;background-repeat:repeat;overflow:hidden;padding:0;cursor:pointer;box-sizing:content-box\"><svg style=\"display:block;\" focusable=\"false\" aria-hidden=\"true\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"100%\" height=\"100%\" viewBox=\"0 0 32 32\"><path fill=\"#fff\" d=\"M28 16c0-6.627-5.373-12-12-12S4 9.373 4 16c0 5.628 3.875 10.35 9.101 11.647v-7.98h-2.474V16H13.1v-1.58c0-4.085 1.849-5.978 5.859-5.978.76 0 2.072.15 2.608.298v3.325c-.283-.03-.775-.045-1.386-.045-1.967 0-2.728.745-2.728 2.683V16h3.92l-.673 3.667h-3.247v8.245C23.395 27.195 28 22.135 28 16Z\"><\/path><\/svg><\/span><\/a><a aria-label=\"X\" class=\"heateor_sss_button_x\" href=\"https:\/\/twitter.com\/intent\/tweet?text=WordPress%20Security%20Alert%3A%20What%20CVE-2026-93485%20Means%20for%20Your%20Website&url=https%3A%2F%2Fwww.webhosting.uk.com%2Fblog%2Fwordpress-security-alert-what-cve-2026-93485-means-for-your-website%2F\" title=\"X\" rel=\"nofollow noopener\" target=\"_blank\" style=\"font-size:32px!important;box-shadow:none;display:inline-block;vertical-align:middle\"><span class=\"heateor_sss_svg heateor_sss_s__default heateor_sss_s_x\" style=\"background-color:#2a2a2a;width:40px;height:40px;display:inline-block;opacity:1;float:left;font-size:32px;box-shadow:none;display:inline-block;font-size:16px;padding:0 4px;vertical-align:middle;background-repeat:repeat;overflow:hidden;padding:0;cursor:pointer;box-sizing:content-box\"><svg width=\"100%\" height=\"100%\" style=\"display:block;\" focusable=\"false\" aria-hidden=\"true\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" viewBox=\"0 0 32 32\"><path fill=\"#fff\" d=\"M21.751 7h3.067l-6.7 7.658L26 25.078h-6.172l-4.833-6.32-5.531 6.32h-3.07l7.167-8.19L6 7h6.328l4.37 5.777L21.75 7Zm-1.076 16.242h1.7L11.404 8.74H9.58l11.094 14.503Z\"><\/path><\/svg><\/span><\/a><a aria-label=\"Linkedin\" class=\"heateor_sss_button_linkedin\" href=\"https:\/\/www.linkedin.com\/sharing\/share-offsite\/?url=https%3A%2F%2Fwww.webhosting.uk.com%2Fblog%2Fwordpress-security-alert-what-cve-2026-93485-means-for-your-website%2F\" title=\"Linkedin\" rel=\"nofollow noopener\" target=\"_blank\" style=\"font-size:32px!important;box-shadow:none;display:inline-block;vertical-align:middle\"><span class=\"heateor_sss_svg heateor_sss_s__default heateor_sss_s_linkedin\" style=\"background-color:#0077b5;width:40px;height:40px;display:inline-block;opacity:1;float:left;font-size:32px;box-shadow:none;display:inline-block;font-size:16px;padding:0 4px;vertical-align:middle;background-repeat:repeat;overflow:hidden;padding:0;cursor:pointer;box-sizing:content-box\"><svg style=\"display:block;\" focusable=\"false\" aria-hidden=\"true\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"100%\" height=\"100%\" viewBox=\"0 0 32 32\"><path d=\"M6.227 12.61h4.19v13.48h-4.19V12.61zm2.095-6.7a2.43 2.43 0 0 1 0 4.86c-1.344 0-2.428-1.09-2.428-2.43s1.084-2.43 2.428-2.43m4.72 6.7h4.02v1.84h.058c.56-1.058 1.927-2.176 3.965-2.176 4.238 0 5.02 2.792 5.02 6.42v7.395h-4.183v-6.56c0-1.564-.03-3.574-2.178-3.574-2.18 0-2.514 1.7-2.514 3.46v6.668h-4.187V12.61z\" fill=\"#fff\"><\/path><\/svg><\/span><\/a><\/div><div class=\"heateorSssClear\"><\/div><\/div><div class='heateorSssClear'><\/div>","protected":false},"author":147,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1735,1503],"tags":[],"ppma_author":[2389],"class_list":["post-21201","post","type-post","status-publish","format-standard","hentry","category-security","category-wordpress"],"authors":[{"term_id":2389,"user_id":147,"is_guest":0,"slug":"niraj-chhajed","display_name":"Niraj Chhajed","avatar_url":{"url":"https:\/\/www.webhosting.uk.com\/blog\/wp-content\/uploads\/2016\/10\/1671629317463.jpg","url2x":"https:\/\/www.webhosting.uk.com\/blog\/wp-content\/uploads\/2016\/10\/1671629317463.jpg"},"author_category":"1","user_url":"https:\/\/www.webhosting.uk.com\/","last_name":"Chhajed","first_name":"Niraj","job_title":"","description":"I'm a SEO and SMM Specialist with a passion for sharing insights on website hosting, development, and technology to help businesses thrive online."}],"_links":{"self":[{"href":"https:\/\/www.webhosting.uk.com\/blog\/wp-json\/wp\/v2\/posts\/21201","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.webhosting.uk.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.webhosting.uk.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.webhosting.uk.com\/blog\/wp-json\/wp\/v2\/users\/147"}],"replies":[{"embeddable":true,"href":"https:\/\/www.webhosting.uk.com\/blog\/wp-json\/wp\/v2\/comments?post=21201"}],"version-history":[{"count":15,"href":"https:\/\/www.webhosting.uk.com\/blog\/wp-json\/wp\/v2\/posts\/21201\/revisions"}],"predecessor-version":[{"id":21216,"href":"https:\/\/www.webhosting.uk.com\/blog\/wp-json\/wp\/v2\/posts\/21201\/revisions\/21216"}],"wp:attachment":[{"href":"https:\/\/www.webhosting.uk.com\/blog\/wp-json\/wp\/v2\/media?parent=21201"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.webhosting.uk.com\/blog\/wp-json\/wp\/v2\/categories?post=21201"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.webhosting.uk.com\/blog\/wp-json\/wp\/v2\/tags?post=21201"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.webhosting.uk.com\/blog\/wp-json\/wp\/v2\/ppma_author?post=21201"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}