Tech

Hackers exploit patched WordPress flaws, leaving up to 90 million sites exposed

WordPress versions 6.9.0 through 7.0.1 remain at risk as researchers estimate tens of millions of websites have not yet applied security patches.

Author
Owen Mercer
Markets and Finance Editor
Published
Draft
Source: TechCrunch · original
Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk
Cybersecurity firms warn of active attacks on critical vulnerabilities despite forced updates

Hackers are actively exploiting two critical security vulnerabilities in WordPress, potentially compromising tens of millions of websites globally. Cybersecurity firms Patchstack, Hexastrike, and WatchTowr have confirmed that the flaws are being exploited in the wild, allowing attackers to take remote control of sites that have not yet updated their software.

The vulnerabilities affect WordPress versions 6.9.0 through 6.9.4 and 7.0.0 to 7.0.1. Although the platform issued forced updates last week to address the severe risks, estimates suggest that up to 90 million sites may remain vulnerable. WordPress’ official statistics indicate that more than 400 million websites run these specific versions, though these figures likely include sites that have already been patched.

Cybersecurity consultant Daniel Card provided a projection based on an analysis of approximately 4,200 WordPress websites. Card determined that less than 15 per cent of his sample was vulnerable. Extrapolating this data across the total population of WordPress sites suggests a global exposure of around 90 million websites.

One of the critical bugs, identified by Adam Kues of Searchlight Cyber, has been dubbed WP2Shell. When paired with the second vulnerability, the flaw allows hackers to gain full remote access to the affected websites. The severity of the issue prompted WordPress to enable forced updates where technically possible to mitigate the risk.

Researchers credited the limited scale of current successful hacks to several protective measures. These include WordPress’ automatic update mechanisms, Cloudflare’s attack blocking services, and the widespread use of web firewalls by site administrators. Automattic and WordPress.org did not immediately respond to requests for comment regarding the ongoing exploitation.

Continue reading

More from Tech

Read next: Open-source tool claims 97 per cent token savings for AI agents
Read next: Valvoline Unveils August 2026 Promotional Offers for Service and Retail Buyers
Read next: Developer Antirez releases native MiniMax H3 inference engine for Apple Silicon