Key facts
- Hackers are exploiting recently patched security vulnerabilities in WordPress.
- The affected WordPress versions are 6.9.0 through 6.9.4 and 7.0.0 to 7.0.1.
- Cybersecurity firms Patchstack, Hexastrike, and WatchTowr have warned of active exploitation.
- Tens of millions of WordPress websites are estimated to be vulnerable.
- One bug, dubbed WP2Shell, allows hackers to gain full remote control of websites.
Hackers are actively exploiting critical security vulnerabilities in WordPress, putting millions of websites at risk of takeover. Cybersecurity firms, including Patchstack, Hexastrike, and WatchTowr, have issued warnings about the ongoing exploitation of these flaws. WordPress recently released patches for two severe bugs and implemented forced updates where possible, but a significant number of websites are still running susceptible versions.
The vulnerabilities affect WordPress versions 6.9.0 through 6.9.4 and 7.0.0 to 7.0.1. While WordPress reports over 400 million websites use these versions, this figure may not account for recent patches. Cybersecurity consultant Daniel Card estimates that fewer than 15% of WordPress sites are vulnerable, which could still translate to around 90 million websites potentially at risk. One of the critical bugs, identified as WP2Shell by Adam Kues of Searchlight Cyber, can allow attackers to gain full remote control of compromised websites.
Researchers have credited WordPress for its automatic update efforts, Cloudflare for blocking attacks, and web firewalls for mitigating some of the risks. Automattic and WordPress.org did not immediately respond to requests for comment.
