Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk
AI-summarised brief · reviewed before publication
Cybersecurity firms report that hackers are actively exploiting two critical WordPress flaws patched last week, targeting sites still running versions 6.9.0‑6.9.4 or 7.0.0‑7.0.1. WordPress responded by forcing automatic updates where possible, but estimates suggest tens of millions of sites remain vulnerable. Patchstack, Hexastrike and WatchTowr confirmed live exploitation, and a sample analysis of 4,200 sites indicated fewer than 15 % are unpatched, implying roughly 90 million WordPress sites could be at risk. The vulnerabilities, dubbed WP2Shell and a companion bug, allow attackers to obtain full remote control. WordPress’ official statistics list over 400 million installations of the affected versions, though many may have already updated. Cloudflare and web‑application firewalls are mitigating some attacks, while Automattic and WordPress.org have not commented as of now.
💡 Why It Matters
- · Unpatched WordPress installations provide a direct pipeline for attackers to plant malware and launch phishing operations against vast numbers of site visitors.