Tuesday, 21 July 2026
Rīga TV

World and Latvian news in one place

TechnologyPublished: 20 July 2026 at 18:36

Hackers Exploit Recently Patched WordPress Bugs, Putting Millions of Websites at Risk

Cybersecurity firms report that hackers are actively exploiting recently patched critical vulnerabilities in WordPress, compromising websites that have not yet updated. Estimates suggest up to 90 million sites may be vulnerable.

Foto: TechCrunch

Hackers are breaking into websites running vulnerable versions of the popular WordPress software, according to multiple cybersecurity firms. Last week, WordPress patched two critical security flaws and urged users to update immediately. The vulnerabilities were so severe that WordPress enabled forced automatic updates where possible.

Since then, security companies Patchstack, Hexastrike, and WatchTowr have warned that hackers are exploiting these vulnerabilities in the wild, taking over websites still running susceptible versions. The affected versions are WordPress 6.9.0 through 6.9.4 and 7.0.0 to 7.0.1. According to WordPress’s official statistics, over 400 million websites use these versions, though this likely doesn't reflect those recently patched.

Cybersecurity consultant Daniel Card examined a sample of about 4,200 WordPress sites and estimated that less than 15% are vulnerable. Applying his projection to the total number of WordPress sites, approximately 90 million remain at risk. Card credited WordPress for pushing automatic updates, Cloudflare for blocking attacks against vulnerable sites, and web firewalls for limiting successful hacks.

One critical bug was found and reported by Adam Kues of Searchlight Cyber, who dubbed it WP2Shell. Combined with the other flaw, attackers can gain full remote control of vulnerable websites. Automattic and WordPress.org did not immediately respond to a request for comment.

Comments

0/1500

Comments are automatically moderated. No hate, threats, personal data or spam.

Loading comments…

More in this category