Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk

← Back to the feed

Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk

TechCrunch · 21 hours ago

Hackers are actively exploiting two recently patched, critical security flaws in WordPress, the widely used blogging software that powers a large share of the world's websites. Cybersecurity firms including Patchstack, Hexastrike and WatchTowr have warned that attackers are taking over sites still running vulnerable versions, prompting concern given how severe the bugs are and how many websites remain unpatched despite WordPress issuing forced updates where possible.

The vulnerabilities affect WordPress versions 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1, with official WordPress statistics suggesting over 400 million sites run these flawed versions, though that figure likely doesn't account for sites already patched. Cybersecurity consultant Daniel Card estimated, from a sample of roughly 4,200 sites, that under 15% remain vulnerable, which would still put the total at around 90 million websites at risk; he credited WordPress's automatic updates, Cloudflare's attack-blocking and web firewalls with limiting the damage so far. One of the flaws, dubbed WP2Shell, was discovered by Adam Kues of Searchlight Cyber, and when combined with the second bug allows hackers to seize full remote control of affected sites. WordPress.org and Automattic did not immediately respond to requests for comment.

  • Hackers are exploiting two critical WordPress security flaws in the wild
  • Tens of millions of sites, possibly around 90 million, remain vulnerable
  • Combined bugs let attackers take full remote control of websites

Cybersecurity Software Technology

Read the full article at the source →