Hackers Exploit Critical WordPress Bugs, Putting Millions of Websites at Risk
Hackers are actively exploiting recently patched WordPress security flaws, leaving millions of websites at risk if they have not installed the latest emergency updates.
Hackers are actively exploiting recently patched security vulnerabilities in WordPress, placing millions of websites at risk if they have not yet installed the latest updates. Multiple cybersecurity firms have confirmed that attackers are targeting websites running vulnerable versions of the world’s most widely used content management system, prompting renewed warnings for website owners to update immediately.
Last week, WordPress released emergency patches for two critical security flaws and urged administrators to install the updates without delay. Due to the severity of the vulnerabilities, the project also enabled automatic updates wherever possible. Since then, cybersecurity companies Patchstack, Hexastrike and WatchTowr have all reported active exploitation attempts, indicating that attackers are already using the flaws to compromise unpatched websites.
Millions of websites could still be vulnerable.
The vulnerable versions include WordPress 6.9.0 through 6.9.4 and versions 7.0.0 to 7.0.1. According to WordPress statistics, more than 400 million websites were running these releases before the security patches became available. However,h the figures are likely to include many sites that have since been updated.
Even with widespread patching efforts, cybersecurity consultant Daniel Card believes a significant number of websites remain exposed. After examining a sample of roughly 3,500 WordPress installations, Card estimated that fewer than 15% were still vulnerable. Applied across the wider WordPress ecosystem, that percentage would still leave around 90 million websites potentially open to attack.
Automatic updates and security services reduce exposure.
Card credited WordPress for rapidly distributing automatic updates, while also highlighting the role played by Cloudflare and website firewalls in blocking exploitation attempts. These protective measures have significantly reduced the number of websites that attackers can successfully compromise, although unpatched installations continue to face immediate risk.
WordPress.org, which oversees development of the open-source software, did not immediately comment on the reports. However, Megan Fox, a spokesperson for Automattic—the company behind WordPress.com and a major contributor to the WordPress project—said all websites hosted across WordPress.com, Pressable, WPVIP and WP.cloud partner services were protected before the public release of the security updates. Once the fixes became available, Automattic immediately deployed them across millions of hosted websites.
Combined vulnerabilities allow complete website takeover
One of the critical vulnerabilities was discovered by Adam Kues of cybersecurity firm Searchlight Cyber, which named the flaw “WP2Shell.” Researchers said that when combined with the second security vulnerability, attackers can gain full remote control over affected WordPress websites, making the flaws particularly dangerous for organisations that have delayed installing the latest updates.
The reports underscore the importance of applying security patches as soon as they become available. With attackers already exploiting the vulnerabilities in real-world attacks, website owners running older versions of WordPress face an increased risk of having their sites compromised until the latest security updates are installed.
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Angry
0
Sad
0
Wow
0