WordPress released version 7.0.2 on 17 July 2026 to address two serious security vulnerabilities.
This isn’t simply a routine update containing a few minor improvements. WordPress has classified one vulnerability as critical and the other as high severity. One of the issues could potentially allow an attacker to run malicious code on an affected website.
Because of the seriousness of the vulnerabilities, WordPress has enabled forced automatic updates for websites running affected versions. That means your website may already have been updated, even if you or your website manager did not initiate it.
That is a good thing. But after an important update, it is still worth checking that your website is both secure and working as expected.
First, check which version your website is running
Log in to your WordPress dashboard and look at the At a Glance panel, or go to Dashboard → Updates.
If your website is running WordPress 7.0 or 7.0.1, it should be updated to 7.0.2 immediately.
WordPress has also released security fixes for affected websites that have not yet moved to version 7:
- WordPress 6.9 websites should be updated to 6.9.5.
- WordPress 6.8 websites should be updated to 6.8.6.
- WordPress versions earlier than 6.8 are not affected by these particular vulnerabilities.
If your dashboard says an automatic update is in progress, allow it to finish before making other changes.
You can read the technical details in the official WordPress 7.0.2 release announcement.
Make sure you have a current backup
A security update should not normally damage a well-maintained website, but every website should have a reliable backup before significant changes are made.
Your backup needs to include both:
- The website files, including WordPress, your theme, plugins and uploaded images
- The database containing your pages, settings, form entries, orders and other content
Ideally, backups should run automatically and be stored somewhere separate from the website’s hosting account.
Don’t assume that a backup system is working simply because a backup plugin is installed. Check the date of the most recent completed backup and make sure you know how it could be restored if necessary.
However, don’t roll a successfully updated website back to a vulnerable WordPress version just because you notice a minor display issue. Investigate the issue or ask your website support provider for help while keeping the security fix in place.
Check the public-facing website
Start with the pages that matter most to your customers.
Open your website in a private or incognito browser window so you are seeing something closer to what a normal visitor sees. Check:
- The homepage
- Main service or product pages
- Contact page
- Navigation menus
- Footer links
- Buttons and calls to action
- Images, galleries and videos
- Any logged-in, membership or customer areas
Look for obvious layout changes, missing images, error messages, unusually slow pages or sections that no longer display correctly.
If the website uses caching or a content delivery network, clear its cache after the update. Otherwise, you may be seeing an outdated version of a page or your visitors may be.
Test the website on mobile
A desktop check isn’t enough. Open the website on your phone and test the main navigation, buttons, forms and important landing pages.
Pay particular attention to elements that behave differently on smaller screens, including:
- Mobile menus
- Pop-ups
- Sticky buttons
- Sliders
- Accordions
- Booking tools
- Embedded maps
- Forms with multiple fields
You don’t need to check every page on every possible device. Concentrate on the routes a real customer is most likely to take.
Submit your important forms
A form can look perfectly normal while failing behind the scenes.
Complete and submit each important form using an email address you can access. Confirm that:
- The form can be submitted without an error.
- The visitor sees an appropriate confirmation message.
- The notification reaches the correct person.
- Any automated confirmation reaches the person who submitted the form.
- The enquiry is recorded in WordPress or your CRM, if applicable.
Test more than the contact form if your website also includes quote requests, registrations, applications, file uploads or newsletter sign-ups.
This is one of the most valuable checks you can make. A broken enquiry form can quietly cost a business leads without producing an obvious website error.
Test payments, bookings and other integrations
If your website carries out a business process, test that process from beginning to end.
Depending on the website, that could include:
- Adding a product to the cart and reaching checkout
- Completing a test payment
- Applying a discount code
- Booking an appointment
- Registering for an event
- Making a donation
- Downloading a purchased file
- Creating or accessing a customer account
- Sending information to a CRM
- Triggering an automated email or workflow
Check what happens after the website action as well. For example, did the order appear in the correct system? Was the booking confirmation sent? Did the new enquiry enter the appropriate CRM pipeline?
A website is not fully working simply because its pages are visible. Its connections and processes need to work too.
Review plugins and themes carefully
WordPress 7.0.2 updates WordPress itself. It does not automatically mean every plugin and theme is current.
Check Dashboard → Updates for other available updates, but avoid installing a large collection of unrelated updates all at once on an important website. Updating in a controlled way makes it easier to identify the cause if something goes wrong.
Plugins or themes that have been abandoned by their developers can present a longer-term security and compatibility risk. Look for anything that:
- Has not been updated for a long time
- Is no longer available from its original source
- Produces warnings or errors
- Duplicates another plugin
- Is installed but no longer needed
Unused plugins and themes should generally be removed rather than merely deactivated, once you have confirmed they are not required.
Look at Site Health
Go to Tools → Site Health in the WordPress dashboard.
Site Health can identify problems involving background updates, scheduled tasks, outdated software, communication with WordPress.org and other technical areas.
Not every recommendation requires urgent action, and some messages need to be interpreted in the context of your particular hosting setup. However, critical issues should not be ignored.
Check for signs of unusual activity
Installing the security update closes the known vulnerabilities, but it does not tell you whether an affected website was previously compromised.
Look for:
- Administrator accounts you do not recognise
- Unexpected new plugins or themes
- Pages or posts you did not create
- Strange redirects
- Spam appearing in search results
- Unexpected file changes
- Sudden increases in server activity
- Security warnings from your host or monitoring service
If anything looks suspicious, avoid simply deleting the visible symptom. A proper investigation may need to examine website files, the database, user accounts and server logs.
Security updates are only part of website maintenance
WordPress updates often happen quietly, which can make website maintenance appear deceptively simple. But the important question is not only, “Did the update install?”
It is also:
- Is the website still available?
- Can customers still contact the business?
- Are payments and bookings working?
- Are emails being delivered?
- Are connected systems receiving the right information?
- Is there a reliable backup if something goes wrong?
A well-maintained website combines security with practical testing. That is how you keep both the website and the business processes behind it working reliably.
If you are unsure whether your WordPress website has been updated, or whether everything is still working properly afterwards, Be Design can carry out a website maintenance and functionality check.