Have you glanced at your WordPress dashboard this week and thought, “Auto-update probably took care of it”? That guess is understandable. It is also not enough this time.
On September 22, 2026, WordPress released version 7.1.2 to close a serious core security issue. Attackers began probing sites within hours. If your site is still on an older build, hoping the background updater ran is not the same as knowing it did.
This walkthrough shows you exactly where to look, what version number you should see, what to do if the site did not update, and why a backup still comes first.
Why this update is different from a routine patch
7.1.2 is a security release, not a feature drop. It fixes a problem in how WordPress resolves page templates. Under certain conditions an unauthenticated visitor could cause WordPress to include a local PHP file it should not. When the server setup and the active theme both line up the wrong way, that can become remote code execution.
You do not need to memorize the technical name. You only need to confirm your site is on a patched version.
WordPress also shipped matching patches for older supported branches:
- WordPress 7.1 branch: 7.1.2
- WordPress 7.0 branch: 7.0.6
- WordPress 6.9 branch: 6.9.9
- WordPress 6.8 branch: 6.8.10
If your site is on an even older line, the same fix was backported as a courtesy. The safest place to be is the current 7.1.2 release. The next safest is the matching patched number on the branch you are actually running.
Automatic background updates help many sites. They do not help every site. Auto-updates can be turned off, blocked by a plugin conflict, delayed by a failed previous update, or skipped on a custom install. That is why a two-minute dashboard check still matters.
For the bigger picture on why core updates cannot wait, see WordPress Security Updates You Cannot Ignore This Year.
Step-by-step: check the version in your dashboard
Set aside five quiet minutes. Use a computer you trust, not a shared front-desk machine.
- Go to your usual WordPress login address. For most sites that is yourdomain.com/wp-admin.
- Sign in with an Administrator account.
- Look at the bottom of the left-hand menu. WordPress often prints the current version there, such as “Version 7.1.2”.
- Also open Dashboard, then Updates. The Updates screen repeats the core version at the top and tells you whether a newer WordPress version is waiting.
- Write the number down, or take a screenshot.
That number is the only thing you need for this check. You are not hunting through files or FTP.
What a patched site should look like
Compare the number you wrote down with the list above.
- If you see 7.1.2 or newer, the September 22 core fix is in place.
- If you are still on the 7.0 line, you want 7.0.6 or newer.
- If you are still on 6.9, you want 6.9.9 or newer.
- If you are still on 6.8, you want 6.8.10 or newer.
Anything older on those branches has not received this particular fix.
The Updates screen may also list plugin and theme updates. Those are important, but they are a separate job. Confirm core first. Plugin-by-plugin checks are covered in How to Tell If a WordPress Plugin You Rely On Just Became a Security Problem and in How to Check If Your WordPress Site Is Updated and Protected Right Now.
If the version is already current
You can stop here for the core question.
Still take one extra look:
- Confirm a recent backup exists (today or yesterday is ideal).
- Glance at the Updates screen for any leftover plugin or theme notices.
- Load your homepage, contact page, and one other important page to make sure the front of the site looks normal.
Then you can get back to the work your site is supposed to support.
If the site did not update
Do not click Update Now the second you see the button. Make a backup first.
A security update is still an update. A plugin or theme that has not been tested against the new core version can break a form, a checkout page, or the admin screen. A current backup turns that from a crisis into an inconvenience.
How to confirm a backup before you proceed:
- If you use a backup plugin, open it and check the date and time of the latest complete backup (files and database).
- If your host runs automatic backups, look at the last successful snapshot in the hosting panel.
- If you are not sure a usable copy exists, create one now and wait until it finishes.
Broader backup habits are in 5 Essential WordPress Maintenance Tasks You Should Never Skip in 2026.
After the backup is confirmed:
- Return to Dashboard, then Updates.
- Update WordPress core only. Leave plugin and theme updates for a second pass.
- When the update finishes, reload the dashboard and confirm the version number changed to 7.1.2 (or the matching older-branch patch).
- Visit the live site. Check the home page, a contact or donation form, the shop or checkout if you have one, and a recent blog post. Look at a phone-sized screen if you can.
- If those pages work, you can move on to pending plugin updates one at a time, testing after each one.
If the update button is missing, grayed out, or fails partway through, common causes include:
- Auto-updates or file editing turned off in wp-config.php
- A security plugin blocking file changes
- Incorrect file permissions
- A must-use plugin or custom drop-in that pins an old version
- Disk space or a failed earlier update sitting in the upgrade folder
In those cases, do not keep clicking the same button. Note the exact version you are on and the error message on the Updates screen. That information is what a technician needs. Do not start deleting random plugins to “see if that helps.”
A staging copy is the safest place to apply a stuck core update first. Many hosts, including KartHost WordPress plans, can provide a staging site so the live storefront stays untouched while you test.
Why a backup still matters even when auto-update is on
Auto-update can apply 7.1.2 while you are asleep. That is useful. It does not replace a restore point.
A patched core version sitting on top of a site with no recent backup still leaves you exposed to a bad plugin combination, a failed database change, or an unrelated problem that appears the same afternoon. The backup is not about distrusting WordPress. It is about giving yourself a way back if anything else on the site objects to the new files.
Think of it as the same habit you already use before a theme change or a WooCommerce update. Security releases deserve that habit too.
How KartHost managed hosting and the Care Plan handle this
If the site is on KartHost Managed WordPress Hosting, core updates are part of the plan. The Convesio-based platform keeps WordPress core, plugins, and many popular themes on a regular update cycle. Daily and monthly backups, malware scanning, and a monthly status report come with that setup, so you are not left guessing whether September 22 landed.
The VIP WordPress Care Plan adds Visual Validator updates for core and plugins, daily security scans, malware cleanup, and a longer off-site backup window. The point of those plans is that the owner does not have to live in the Updates screen after every WordPress.org announcement.
Self-managed or DIY WordPress hosting still needs the dashboard check above. Managed hosting does not remove the value of glancing at the version number once. It does remove the need to treat every security release as a late-night project.
Details on the hosting side are on Managed WordPress Hosting. The Care Plan is described at VIP WordPress Care Plan.
A short checklist you can use today
- Log into wp-admin.
- Read the version at the bottom of the left menu and on Dashboard > Updates.
- Confirm it is 7.1.2, 7.0.6, 6.9.9, 6.8.10, or newer on that same branch.
- If it is current, confirm a recent backup and spot-check a few live pages.
- If it is not current, confirm a full backup first, then update core only, then re-check the version number and key pages.
- Save plugin and theme updates for a second pass, one item at a time.
That is the whole job for this release. You do not need to become a security researcher. You only need to know which number your site is showing.
Your WordPress site is often the first place customers meet the business. A five-minute version check after a core security release is one of the simplest ways to keep that door in good shape.
