Apps & Consumer
Hackers exploit newly patched WordPress bugs, putting millions of sites at risk
Cybersecurity firms Patchstack, Hexastrike, and WatchTowr say hackers are actively exploiting two critical WordPress vulnerabilities patched last week, with one estimate putting the number of still-vulnerable sites at tens of millions.
Hackers are breaking into websites running vulnerable versions of WordPress, according to several cybersecurity firms, with one estimate putting the number of exposed sites at tens of millions as of Monday.
WordPress patched two critical security flaws last week, urging site operators to update “immediately,” and the vulnerabilities were severe enough that WordPress enabled forced updates where possible. Since then, cybersecurity companies Patchstack, Hexastrike, and WatchTowr have all warned that hackers are exploiting the flaws in the wild — taking over websites still running the vulnerable versions.
The affected releases are WordPress 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. WordPress’s own statistics show more than 400 million websites run those versions, though that figure likely doesn’t reflect sites that have already been patched. Cybersecurity consultant Daniel Card told TechCrunch that, in a sample of around 3,500 WordPress sites he examined, fewer than 15% were vulnerable; applying that share across the full population of WordPress websites would still put the total at around 90 million.
Card credited WordPress for pushing automatic updates, Cloudflare for blocking attacks against vulnerable sites, and web application firewalls and other protections for limiting the number of sites that remain exploitable.
WordPress.org, which develops WordPress’s open-source code, did not immediately respond to a request for comment. Megan Fox, a spokesperson for Automattic — the company behind WordPress.com — told TechCrunch that “all sites hosted by Automattic, including WordPress.com, Pressable, WPVIP, and WP.cloud partners, were protected even before the release. When the code updates were published, we deployed them immediately across millions of sites.”
One of the two critical bugs, dubbed WP2Shell, was found and reported by Adam Kues of cybersecurity firm Searchlight Cyber. Paired with the second bug, it lets hackers take full remote control of vulnerable websites.
Why it matters
WordPress still powers a large share of the public web, so unpatched installations at this scale give attackers a wide, slow-moving pool of sites to compromise well after the initial disclosure.