HomeStartups & TechnologyMillions of WordPress sites exposed to active exploit campai
Startups & Technology

Millions of WordPress sites exposed to active exploit campaign

Tens of millions of WordPress sites remain vulnerable to critical security flaws, with hackers actively compromising unpatched installations. Cybersecurity firms Patchstack, Hexastrike, and WatchTowr report that attackers are weaponizing the bugs just days after developers issued emergency patches and triggered forced updates to mitigate the risk.

Millions of WordPress sites exposed to active exploit campaign

The vulnerabilities affect WordPress versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. While official statistics suggest over 400 million sites run these versions, current patching rates remain difficult to quantify. Cybersecurity consultant Daniel Card analyzed a sample of 4,200 sites and projected that roughly 15% remain exposed. If accurate, this estimate implies that approximately 90 million websites could still be vulnerable to remote takeover.

Researchers at Searchlight Cyber identified one of the primary flaws, dubbed WP2Shell by analyst Adam Kues. When combined with a second critical vulnerability, the exploit allows unauthorized users to gain full remote control over affected servers. While Cloudflare and various web firewalls have begun blocking incoming attacks, the sheer scale of the WordPress ecosystem leaves a massive surface area for exploitation. Automattic and the WordPress.org development team have not commented on the ongoing incident.

Comments (0)

Leave a comment

No comments yet. Be the first!