Product NewsCategory

Critical WordPress Security Update (7.0.2): What GoDaddy Customers Need to Know

3 min read
Justin Nealey
security in scrabble letters
Image credit: Pexels - Miguel Á. Padriñán

Summary

The WordPress Security Team has released WordPress 7.0.2 to address a critical security vulnerability affecting WordPress core...

This vulnerability impacts all versions of WordPress, 6.8 and newer. Because this is a critical vulnerability, we strongly recommend that all customers running WordPress, across VPS, Web Hosting, and Managed Hosting for WordPress, update immediately.

For full technical details, including the CVE identifier and official severity rating, see the official WordPress 7.0.2 release announcement.


Who is affected?

This issue affects ALL self-hosted WordPress installations of WordPress 6.8 and greater, including but not limited to:

  • VPS customers (Self-Managed and Managed) running WordPress.
  • Web Hosting & Windows Hosting customers running WordPress.
  • Managed Hosting for WordPress customers.
  • Pagely (A GoDaddy Brand)

What GoDaddy is doing

GoDaddy automatically pushed the fix to all Managed Hosting for WordPress sites. Rather than forcing every site onto a single version, we backported the security patch to each supported release line, so your site was updated to the patched version of the branch it was already running: 6.8.x sites went to 6.8.6, 6.9.x sites to 6.9.5, and 7.0.x sites to 7.0.2. If your site shows 6.8.6, 6.9.5, or 7.0.2, it is protected.

For Web Hosting customers, GoDaddy is deploying additional protective measures at the platform and infrastructure level to help reduce risk while you update. These measures are a temporary safeguard, not a substitute for patching. You are responsible for updating WordPress core to the latest version as soon as possible.

For VPS customers (Self-Managed and Managed), customers manage their own WordPress installation and are responsible for applying the update themselves, unless automatic updates are enabled, in which case the update will be applied automatically. Instructions are below.


What you need to do (VPS customers, Self-Managed and Managed)

  • If you have automatic WordPress updates enabled, the patched version will be applied automatically.
  • If you manage your own WordPress updates, update WordPress core to version 7.0.2 via your WordPress admin dashboard (Dashboard > Updates) or WP-CLI: wp core update
  • Back up your site before applying updates, if you haven't already set up automated backups.
  • Verify the update by checking your WordPress version under Dashboard > At a Glance.

What you need to do (Web Hosting & Windows Hosting customers)

  • GoDaddy has applied protective measures at the platform level to help reduce exposure while the official patch is rolled out.
  • We still recommend confirming your WordPress core version is up to date (7.0.2).

What you need to do (Managed Hosting for WordPress customers)

No action needed. GoDaddy has already applied the fix to your site. You do not need to be on 7.0.2 specifically to be protected: we backported the patch to every supported version line, so sites on 6.8.6, 6.9.5, or 7.0.2 all have the fix. Which of those your site landed on depends on the release line it was running before the update.