Hackers exploit patched WordPress flaws, leaving up to 90 million sites exposed
WordPress versions 6.9.0 through 7.0.1 remain at risk as researchers estimate tens of millions of websites have not yet applied security patches.

Hackers are actively exploiting two critical security vulnerabilities in WordPress, potentially compromising tens of millions of websites globally. Cybersecurity firms Patchstack, Hexastrike, and WatchTowr have confirmed that the flaws are being exploited in the wild, allowing attackers to take remote control of sites that have not yet updated their software.
The vulnerabilities affect WordPress versions 6.9.0 through 6.9.4 and 7.0.0 to 7.0.1. Although the platform issued forced updates last week to address the severe risks, estimates suggest that up to 90 million sites may remain vulnerable. WordPress’ official statistics indicate that more than 400 million websites run these specific versions, though these figures likely include sites that have already been patched.
Cybersecurity consultant Daniel Card provided a projection based on an analysis of approximately 4,200 WordPress websites. Card determined that less than 15 per cent of his sample was vulnerable. Extrapolating this data across the total population of WordPress sites suggests a global exposure of around 90 million websites.
One of the critical bugs, identified by Adam Kues of Searchlight Cyber, has been dubbed WP2Shell. When paired with the second vulnerability, the flaw allows hackers to gain full remote access to the affected websites. The severity of the issue prompted WordPress to enable forced updates where technically possible to mitigate the risk.
Researchers credited the limited scale of current successful hacks to several protective measures. These include WordPress’ automatic update mechanisms, Cloudflare’s attack blocking services, and the widespread use of web firewalls by site administrators. Automattic and WordPress.org did not immediately respond to requests for comment regarding the ongoing exploitation.
