Hackers are exploiting freshly patched WordPress flaws, putting millions of sites at risk

Hackers are actively breaking into websites running vulnerable versions of WordPress, and the scale of the problem is significant. According to TechCrunch, cybersecurity firms Patchstack, Hexastrike, and WatchTowr have all confirmed that attackers are exploiting the flaws in the wild, meaning real websites are being taken over right now.

WordPress patched two critical security vulnerabilities last week and told site owners to update “immediately.” The bugs are serious enough that WordPress pushed forced automatic updates where it could. Despite that, a large number of sites remain exposed.

The vulnerable versions span WordPress 6.9.0 through 6.9.4, and 7.0.0 through 7.0.1. WordPress’ own statistics suggest more than 400 million websites run those versions, though that figure almost certainly includes many sites that have since been patched.

A more grounded estimate comes from cybersecurity consultant Daniel Card, who analyzed a sample of around 3,500 WordPress sites and found that fewer than 15% are still vulnerable. Applied across the full population of WordPress-powered sites on the internet, that still puts the number of at-risk websites at roughly 90 million. That is a large target.

One of the two critical bugs was discovered by Adam Kues at cybersecurity firm Searchlight Cyber, which named it WP2Shell. When combined with the second vulnerability, an attacker can gain full remote control of an affected website. That is about as bad as it gets.

Card noted that the situation could be much worse without a few factors working in defenders’ favor:

  • WordPress’ automatic update push has already protected many sites
  • Cloudflare has been blocking attacks against vulnerable websites
  • Sites using web application firewalls have an added layer of protection

Automattic, the company behind WordPress.com and a major contributor to the open source project, said it had things covered before the public patch even dropped. Spokesperson Megan Fox told TechCrunch that “all sites hosted by Automattic, including WordPress.com, Pressable, WPVIP, and WP.cloud partners, were protected even before the release. When the code updates were published, we deployed them immediately across millions of sites.”

WordPress.org, which oversees the open source codebase, did not respond to a request for comment.

This situation is a good reminder of why keeping software updated matters. WordPress powers a huge portion of the web, which makes it a constant target. When critical flaws surface, the window between patch release and active exploitation is shrinking. Anyone running a self-hosted WordPress site who has not yet updated should treat this as urgent.