Tech

WordPress Security Flaw Under Active Attack as Hackers Target Millions of Websites

Website administrators are being urged to update their installations immediately after security researchers confirmed that hackers are actively exploiting a critical WordPress security vulnerability affecting older versions of the world’s most popular content management system.

The attacks began shortly after WordPress released emergency security patches addressing two high-severity vulnerabilities. Although the fixes are already available, cybersecurity firms report that threat actors have quickly started targeting websites that have yet to install the updates.

Critical Vulnerabilities Are Already Being Exploited

According to cybersecurity companies Patchstack, Hexastrike, and WatchTowr, attackers are actively scanning the internet for vulnerable WordPress websites and attempting to compromise them before administrators apply the latest security patches.

The affected versions include:

  • WordPress 6.9.0 to 6.9.4
  • WordPress 7.0.0 to 7.0.1

Security experts warn that websites still running these versions remain vulnerable until updated.

Millions of Websites Could Still Be at Risk

Official WordPress statistics indicate that more than 400 million websites have used the affected versions worldwide.

While many websites have already received updates, security consultant Daniel Card estimates that roughly 15% of installations may still be vulnerable. That could translate to as many as 90 million websites remaining exposed to potential attacks.

Although the exact number continues to decrease as administrators update their systems, cybersecurity experts stress that delaying updates significantly increases the risk of compromise.

Multiple Layers of Protection Help Limit Damage

Fortunately, several defensive measures have helped reduce the overall impact.

WordPress enabled automatic security updates for many installations, while services such as Cloudflare have been blocking malicious traffic targeting vulnerable websites. In addition, organizations using properly configured web application firewalls (WAFs) have gained another important layer of protection against exploitation attempts.

As a result, the number of confirmed successful compromises remains considerably lower than the overall number of potentially vulnerable websites.

WordPress.com Sites Were Protected Before Public Disclosure

Automattic, the company behind WordPress.com, confirmed that websites hosted on its managed platforms—including Pressable, WPVIP, and WP.cloud—received protection before the security patches became publicly available.

The company also distributed the fixes across millions of hosted websites immediately after the updates were released, helping minimize the opportunity for attackers to exploit the vulnerabilities.

What Is WP2Shell?

The vulnerabilities were discovered by Adam Kues, a security researcher at Searchlight Cyber, who collectively named the exploit chain WP2Shell.

When combined, the two vulnerabilities can allow attackers to gain remote control over affected WordPress websites, making them especially dangerous for organizations that have not yet updated their installations.

Because the attacks are already occurring in the wild, cybersecurity professionals strongly recommend that all WordPress administrators verify their installed version and apply the latest security updates as soon as possible.

Update Your Website Immediately

For website owners and administrators, the message from security experts is straightforward: update immediately.

Keeping WordPress, plugins, themes, and security tools fully updated remains one of the most effective ways to protect websites against newly discovered vulnerabilities. As attackers continue to automate internet-wide scans for outdated installations, delaying even a routine security update can significantly increase the risk of compromise.

Read more: Latest Technology News

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button