The Daily
Menu
Tech

Millions of WordPress sites remain vulnerable to active exploitation following critical security patches

Cybersecurity firms report that hackers are actively exploiting two critical vulnerabilities in recent WordPress versions, potentially impacting millions of websites. While automated updates have mitigated some risk, experts urge administrators to verify their software versions immediately.

By Ada

Millions of websites running on the WordPress platform are currently at risk as threat actors actively exploit two critical security vulnerabilities patched by the software developers last week. The flaws, which affect versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1, allow for full remote control of affected systems when chained together. According to TechCrunch, the severity of these bugs prompted WordPress to initiate forced updates where possible to protect the ecosystem.

WordPress security vulnerability illustration | Source: TechCrunch
WordPress security vulnerability illustration | Source: TechCrunch

Security researchers from firms including Patchstack, Hexastrike, and WatchTowr have confirmed that exploitation is occurring in the wild. One of the vulnerabilities, identified as WP2Shell by researcher Adam Kues of Searchlight Cyber, serves as a primary vector for unauthorized access. While official statistics suggest that over 400 million sites may have been running the affected versions, cybersecurity consultant Daniel Card estimates that the actual number of currently vulnerable sites is likely closer to 90 million, accounting for those that have already applied the necessary patches.

The mechanics of the defense effort have been multi-layered. Automattic, the company behind WordPress.com, stated that its hosted services—including Pressable, WPVIP, and WP.cloud partners—were secured prior to the public release of the patches. Furthermore, the deployment of web application firewalls and proactive blocking by services like Cloudflare have helped limit the scope of successful attacks. Despite these measures, the sheer scale of the WordPress ecosystem makes it a persistent target for automated exploitation tools.

This incident highlights the ongoing tension between the ubiquity of open-source content management systems and the speed at which security patches must be deployed to maintain integrity. While the automated update mechanism has significantly reduced the window of opportunity for attackers, the remaining vulnerable sites represent a substantial surface area for malicious activity. As the situation evolves, the primary defense for site administrators remains the immediate verification of their software version and the application of the latest security updates provided by the WordPress project.