WordPress core updates and how to install them without breaking your site
A WordPress core update replaces the files that make up WordPress itself and then brings the database up to date, so the safe routine is a backup first, the update from Dashboard > Updates or WP-CLI, and a check of the site afterwards. This guide covers each step, how to fix an update that fails, and how safe WordPress updates work when you look after more than one site.

The short answer
A WordPress core update installs a newer version of WordPress itself. Minor releases, such as 7.1.3, fix bugs and security issues and install on their own on most sites; major releases, such as 7.1, add features and need more care. Back up first, update from Dashboard > Updates, WP-CLI or by hand, let the database update finish, then check the site.
- Back up the files and the database.
- Check your PHP version, plugins and theme.
- Pick a quiet time.
- Update from Dashboard > Updates, WP-CLI or by hand.
- Let the database update finish.
- Check key pages, forms, wp-admin and Site Health.
- If it breaks, restore the backup.
There is no rollback button for core, so that backup is your way back. Running several sites? See core updates on many sites.
What is a WordPress core update?
A WordPress core update replaces the files that make up WordPress itself with a newer release: the wp-admin and wp-includes folders and the files in the site's root folder, such as wp-login.php.
It leaves your content alone. Posts, pages and settings live in the database, and themes, plugins and uploads live in wp-content, which a core update skips apart from adding new default themes and translations. Your wp-config.php file is not touched either.
Every core update has two halves: new files, then a database update so the database matches them. Either half can stall, so this guide covers both.
What is the difference between a major and a minor WordPress release?
A major release changes the first two numbers of the version, such as 7.0 to 7.1, and brings new features. A minor release changes the third number, such as 7.1.2 to 7.1.3, and fixes bugs, security issues or both.
The jump from 6.9 to 7.0 was not bigger than usual. WordPress counts major versions in tenths, and its version numbering page says: "Version 4.0 is no different than 3.9 and 4.1."
| Major release | Minor release | |
|---|---|---|
| Recent example | 7.1 "Mary Lou", 19 August 2026 | 7.1.3, 6 October 2026 |
| What it contains | New features, sometimes new server requirements | Bug fixes and security fixes |
| Installs on its own by default? | Only on sites first installed on WordPress 5.6 or later | Yes, on most sites |
| How careful to be | Back up, check PHP and plugins, try it on a copy first | Back up and install soon |
Sources: WordPress.org release posts and handbooks, checked 10 October 2026.
The plugin handbook draws the same line: a plugin's "Tested up to" field "ignores minor versions, as plugins shouldn't break with a minor update."
What is the current version of WordPress?
On 10 October 2026, the current version is WordPress 7.1.3, a maintenance and security release from 6 October 2026 with 7 security fixes and 4 bug fixes. Its announcement asks you to "update your sites immediately."
- 6.9 "Gene": major release, 2 December 2025.
- 7.0 "Armstrong": major release, 20 May 2026, which raised the minimum PHP version to 7.4.
- 7.1 "Mary Lou": major release, 19 August 2026, followed by 7.1.1, 7.1.2 and 7.1.3 between 17 September and 6 October.
- 7.2: planned for 10 December 2026, a date the WordPress roadmap calls "for rough planning purposes only."
The roadmap aimed for three major releases in 2026. Older branches still get security backports (7.0.7 shipped the same day as 7.1.3), but the release archive says: "Only the most recent in the 7.1 series is safe to use and actively maintained."
To see a site's version, look at the bottom of any wp-admin screen or run wp core version.
Does WordPress update core on its own?
Partly. By default WordPress installs minor core releases on its own on most sites, and sites first installed on WordPress 5.6 or later get major releases automatically too. You can change that under Dashboard > Updates or in wp-config.php, and our guide to WordPress automatic updates explains every setting. The checks below apply either way.
What should you check before updating WordPress core?
Check four things before a core update: a backup you can restore, your server versions, your plugins and theme, and the timing. For a minor release the backup matters most; for a major release, all four do.
A backup you can restore
Back up the files and the database right before the update, not last night, and keep the copy off the server. WordPress's own Updates screen asks for it: "Before updating, please back up your database and files." Off-site WordPress backups keep that copy where a broken server cannot reach it.
PHP and database versions
WordPress.org recommends PHP 8.3 or greater, and MySQL 8.0 or MariaDB 10.11 or greater. WordPress still runs on PHP 7.4 and MySQL 5.5.5, but those versions are past their end of life, and the Updates screen will not offer a release your server cannot run.
Major releases can raise that floor: WordPress 7.0 dropped PHP 7.2 and 7.3, and sites still on them stay on the 6.9 branch. You will find your versions under Tools > Site Health > Info.
Plugins and theme
For a major release, check your important plugins' "Tested up to" value and recent changelog on WordPress.org, ask vendors about premium plugins, and treat a plugin nobody has updated in years as a risk. Our guide to WordPress plugin management covers keeping that list short. On a site that matters, try the update on a copy of the site first; many hosts can make one in a click.
Timing
Update when traffic is low and someone can check the site straight afterwards. Security releases are the exception: install them soon.
How to update WordPress core safely, step by step
These seven steps work with any method, whether you click a button, run WP-CLI or upload the files by hand.
- Take a full backup. Back up the files and the database right before the update and store the copy off the server.
- Check the requirements. Find your PHP and database versions under Tools > Site Health > Info and compare them with what the release needs.
- Check plugins and your theme. For a major release, check that your important plugins and your theme support it.
- Pick a quiet time. Update when traffic is low and someone can check the site afterwards. On several sites, update one first.
- Run the update. Use Dashboard > Updates, run wp core update with WP-CLI, or replace the files by hand.
- Finish the database update. If wp-admin shows Database Update Required, click Update WordPress Database, or run wp core update-db.
- Check the site. Open key pages, forms and wp-admin, then check Site Health and the error log. If something broke, restore the backup.
How do you update WordPress core: dashboard, WP-CLI or by hand?
The dashboard suits most sites, WP-CLI suits anyone with SSH access, and a manual update is the fallback when the other two fail.
| Method | Best for | The database update |
|---|---|---|
| Dashboard > Updates | Most sites, with an administrator login | Runs on its own; if it does not, wp-admin asks you |
| WP-CLI | Developers and anyone with SSH access | Run wp core update-db to be sure |
| Manual upload | When the other two fail | Visit wp-admin and follow the prompt |
Sources: Updating WordPress on WordPress.org and the WP-CLI handbook, checked 10 October 2026.
From the dashboard
- Go to Dashboard > Updates in wp-admin.
- Click the button to update to the new version (older versions of WordPress label it Update Now) and stay on the page until WordPress opens the About screen.
- If WordPress asks for FTP details, it cannot write its own files. Enter the details from your host, or ask the host to fix the file ownership.
With WP-CLI
Connect over SSH, go to the site's folder and run:
wp core version # the version you have now
wp core check-update # what is available
wp core update # update to the latest version
wp core update-db # run the database update
wp core verify-checksums # check core files against WordPress.org
Add --minor to install only minor releases or --version=7.1.3 to pick a version, and use wp core update-db --network on a multisite network.
By hand
Use a manual update when the dashboard update keeps failing. The WordPress.org steps, in short:
- Back up, then download and unpack the latest WordPress zip from WordPress.org.
- Deactivate your plugins.
- Replace the
wp-adminandwp-includesfolders on the server with the new ones. - Upload the loose root files and the contents of the new
wp-contentfolder, overwriting files. Never delete yourwp-contentfolder;wp-config.phpstays as it is. - Delete any leftover
.maintenancefile, visit/wp-admin/to run the database update, then reactivate your plugins and clear caches.
What happens during a WordPress core update?
WordPress puts the site into maintenance mode, copies the new files, switches maintenance mode off and then updates the database in a separate request. The diagram at the top shows the order, taken from WordPress core's update_core() function.
While the .maintenance file exists, visitors see "Briefly unavailable for scheduled maintenance. Check back in a minute." WordPress ignores the file once it is 10 minutes old. The database update is a request the site sends to its own wp-admin/upgrade.php. If a host or firewall blocks it, the database waits until someone opens wp-admin, where WordPress compares the stored database version with the one the new files expect and shows Database Update Required.
What should you check after updating WordPress core?
Check as soon as the update finishes, because a core update can complete without an error and still leave a page broken.
- Key pages and forms. Open the pages that earn money in a private window, send a test form, try checkout and log in.
- wp-admin. Dashboard > Updates should say "You have the latest version of WordPress."
- Site Health. Tools > Site Health flags critical issues, such as a failed loopback request.
- The error log. If something looks wrong, turn on the debug log, read
wp-content/debug.log, then turn it off again; WordPress advises against debug tools on live sites. - Core files and caches. Run
wp core verify-checksums, and clear page and CDN caches.
If a page broke, WordPress's upgrade guide points to plugins first and suggests deactivating the plugins that do not come with WordPress. For sites you cannot open by hand, WordPress uptime monitoring tells you when a site stops answering, and visual regression testing compares screenshots from before and after a change to catch layouts that break without an error.
What should you do when a WordPress core update fails?
Work out which state the site is in and fix that one thing. Back up the current state first, so you can undo your own fixes.
"Briefly unavailable for scheduled maintenance"
The update stopped before WordPress removed its .maintenance file. Delete it from the WordPress root folder, the one that holds wp-admin and wp-includes, using FTP or your host's file manager; that also clears the failed update notice in wp-admin. Then run the update again, because it may have stopped part way.
"Database Update Required" keeps coming back
Click Update WordPress Database once and wait for "Update Complete". If the screen returns:
- Run
wp core update-db, orwp core check-update-dbto see whether an update is still needed. - Clear any persistent object cache, such as Redis or Memcached, or rename
wp-content/object-cache.phpfor a moment. A cache still serving the old database version sends you back to the same screen. - Check the error log for database errors, and ask your host whether the database user may change tables.
"Another update is currently in progress"
WordPress locks core updates while one runs, and the lock expires after 15 minutes. If you are sure nothing is running, wait, or remove the lock with wp option delete core_updater.lock, as the WP-CLI handbook suggests.
A critical error or a blank page
The new files are in place, but a plugin or theme fails on them. Check the site admin's inbox for WordPress's recovery mode link, then follow our guides to the WordPress critical error and the white screen of death.
The update email says it failed
After a failed automatic core update, WordPress emails the site admin. "WordPress 7.1.3 is available. Please update!" means no core files were changed, so the old version still runs; update from the dashboard. "URGENT: Your site may be down due to a failed update" means it failed after copying started: check the site now, then restore your backup or update by hand. WordPress will not try another automatic core update until someone completes one by hand.
Not enough disk space, or files WordPress cannot write
WordPress stops with "There is not enough free disk space to complete the update." on a full server, and asks for FTP details when it cannot write its own files. Tools > Site Health > Info shows directory sizes and which folders WordPress can write to; free up space or fix the ownership with your host, then update again.
How do you go back to the previous version of WordPress?
Restore the full backup you took before the update. WordPress has no button that takes core back to an earlier version: Dashboard > Updates only offers to update, or to re-install the version you have. Its one built-in safety net is narrow: when an automatic background update fails while copying files, WordPress tries to put the previous version back.
WP-CLI can install an older release with --force:
wp core update --version=7.0.7 --force
Use it with care. WordPress's upgrade guide calls rolling back "usually not recommended": newer versions carry security fixes, and database changes between versions can cause complications. It also warns that without a full backup made before the update "a successful rollback is near impossible." If you reinstall an older release, restore the pre-update database too, and treat it as a short stop.
A full restore is simpler, though it also removes anything that changed since the backup, such as new orders. Restore and disaster recovery tools put back the whole site, only the database, or chosen files.
How do you keep WordPress core current on many sites?
Run core updates from one list rather than one wp-admin at a time, with the same routine everywhere: a copy first, the update, the database step, then a check. Logging in to each site works for a handful of sites; beyond that, updates get postponed and sites drift behind.
- Leave minor releases on automatic, so security fixes arrive without you.
- Hold major releases for a planned window, and update one site first.
- Track which site runs which version, and watch every site from outside, so a site that goes down after an update is noticed before a client calls.
How WPCentrify handles WordPress core updates
WPCentrify, a hosted WordPress management platform for anyone responsible for more than one WordPress site, runs core updates through its bulk updates feature. (Disclosure: WPCentrify is our product.)
- One list of pending updates for WordPress core, plugins and themes across every connected site, grouped by release.
- A copy first. WPCentrify sends the core update to every site you choose and copies the database and WordPress's own files before it runs.
- The database step finished. It completes the database upgrade WordPress needs afterwards, even on hosts that block the request WordPress normally uses for it.
- Uptime checks every 60 seconds from 3 locations (Malaysia, Canada and the USA), with an email alert only when locations on different providers agree a site is down, after three failed checks in a row.
One limit, stated plainly: automatic rollback in WPCentrify covers plugin and theme updates (after a PHP fatal error, a 5xx server error or a visual break), not core updates. For core, the copy taken before the update is your way back.
On the account we use ourselves, which manages 18 WordPress sites, the update list showed 11 updates awaiting review on 10 October 2026, the kind of list nobody wants to work through one wp-admin at a time. Core updates are one part of our WordPress website management platform, free during early access.
Sources
- WordPress 7.1.3 Maintenance and Security Release and the release announcements, WordPress.org News
- Release Archive, Roadmap and Requirements, WordPress.org
- Version Numbering, Core Contributor Handbook
- Dropping support for PHP 7.2 and 7.3, Make WordPress Core
- Updating WordPress and Site Health screen, WordPress.org documentation
- Upgrading WordPress, Common WordPress errors and Debugging in WordPress, Advanced Administration Handbook
- wp core version, wp core check-update, wp core update, wp core update-db, wp core check-update-db and wp core verify-checksums, WP-CLI handbook
- update_core(), wp_maintenance(), wp_is_maintenance_mode(), wp_upgrade(), Core_Upgrader::upgrade(), WP_Automatic_Updater and wp-admin/update-core.php, WordPress code reference
- How your readme.txt works, Plugin Handbook
All sources checked on 10 October 2026.
Questions about WordPress core updates
Back up the site, then go to Dashboard > Updates in wp-admin and click the button to update. With WP-CLI, run wp core update and then wp core update-db. If both fail, replace the core files by hand, keeping wp-content and wp-config.php.
Minor releases are low risk and carry security fixes, so install them promptly. Major releases change more at once, so back up first, check your PHP version and plugins, and check the site afterwards.
A major release changes the first two numbers of the version, such as 7.0 to 7.1, and adds features. A minor release changes the third number, such as 7.1.2 to 7.1.3, and fixes bugs or security issues.
On 10 October 2026 it is WordPress 7.1.3, a maintenance and security release from 6 October 2026. The next major release, WordPress 7.2, is planned for 10 December 2026.
Install minor and security releases as soon as they come out, which WordPress does on its own on most sites. Plan each major release, a few a year, for a quiet time after a backup and a plugin check.
No. A core update replaces WordPress's own files and updates the database, but leaves your posts, pages, settings, themes, plugins and uploads in place. Back up anyway, because a failed update can still break the site.
Not with a button. The reliable way back is the full backup you took before updating. WP-CLI can reinstall an older version with wp core update and the --version and --force options, but WordPress advises against rolling back because the database may already have changed.
An update stopped before WordPress deleted the .maintenance file in the site root. Delete that file with FTP or your host's file manager, then run the update again, because it may have stopped part way.
The new WordPress files expect a newer database version than the one stored. Click Update WordPress Database and wait for Update Complete. If the screen keeps coming back, run wp core update-db and clear any persistent object cache.
Use WP-CLI on each server, or a management tool connected to every site. WPCentrify, our own product, sends a core update to every site you choose, copies the database and WordPress's own files first, and finishes the database upgrade afterwards.
Related reading
Bulk updates
WordPress core, plugin and theme updates across every site, from one list.
See the featureWordPress automatic updates
What WordPress updates by default and how to turn each part on or off.
Read the guideWordPress critical error
Causes and fixes for the critical error message, from recovery mode to the error log.
Read the guideMore on this topic: safe WordPress updates with automatic rollback and managing WordPress plugins.
Keep WordPress current on every site you manage
Core, plugin and theme updates from one list, a copy of the database and core files before each core update it runs, and uptime checks every 60 seconds from 3 locations.
Free during early access. No credit card required.