WordPress just updated millions of sites without asking. that's rarer than you think — and here's how to check it worked

The forced auto-update push behind the wp2shell fix is a mechanism WordPress has used only a handful of times. What it is, why they broke the 'we…

Aliteq
Priya Nair · Software & Systems Editor

The short answer

WordPress's auto-update system can push a security release even to sites that never enabled automatic updates — a 'forced update.' It's reserved for severe, widely-exploitable core flaws, and…

Forced updates ride the same background auto-update infrastructure that's been in core since WordPress 3.7 (2013), but override the site's opt-out for critical security releases.

WordPress reserves them for rare, severe cases — past examples include forced pushes for serious vulnerabilities where mass exploitation was likely.

They don't always reach everyone: sites that fully disabled auto-updates via constants or filters, or whose servers block outbound update checks, can be missed.

The only safe assumption is to verify, not trust: check your version reads 6.9.5, 7.0.2, or 6.8.6 in the admin footer.

The only move that matters

Don't reason about whether the forced update *should* have reached you. Just look. Log into wp-admin and read the version number in the footer, or check Dashboard → Updates. If it says 6.9.5, 7.0.2…

Aliteq

Read the full story

WordPress just updated millions of sites without asking. that's rarer than you think — and here's how to check it worked

Read the full story on Aliteq