17 days ago
TechCrunch Jul 20, 2026

Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk

Hackers are actively exploiting two recently fixed critical security vulnerabilities in WordPress software, putting millions of websites at risk of unauthorized remote access. These flaws, identified in versions ranging from 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1, have led WordPress to issue urgent updates and implement forced automatic patches where possible. Despite these efforts, many sites remain vulnerable as several cybersecurity firms including Patchstack, Hexastrike, and WatchTowr have confirmed ongoing exploitation in the wild.

An estimate from cybersecurity consultant Daniel Card suggests that while fewer than 15% of WordPress websites remain vulnerable, this still translates to approximately 90 million sites potentially exposed to attacks. WordPress powers over 400 million websites globally, making these vulnerabilities especially consequential. The company behind WordPress, Automattic, has stated that all sites hosted by its platforms were protected prior to the patch release and that updates were rapidly deployed across millions of sites.

The critical security issues, known collectively as WP2Shell, were discovered by cybersecurity researcher Adam Kues of Searchlight Cyber. The combined vulnerabilities give attackers the capability to fully take control of affected WordPress websites remotely. Protective measures such as Cloudflare’s blocking of attacks and the use of web firewalls have so far helped limit the impact on sites that have yet to apply the patches.

This incident highlights the ongoing security challenges facing widely used open source platforms like WordPress. It underscores the importance for site operators to promptly update their software to defend against active threats. WordPress.org has not commented directly on the situation yet, but the company’s swift patch deployment underscores the urgency with which it treats such serious security issues.

0
0 Read source
Share this post
Facebook Twitter LinkedIn

Discussion

0 comments

No comments yet

Start the discussion with a take, question, or market read.