Hackers exploit patched WordPress bugs, millions of sites at risk
According to cybersecurity firms, hackers are breaking into websites running vulnerable versions of WordPress. Last week, WordPress patched two critical security flaws and urged users to update immediately, enabling forced updates where possible. Cybersecurity companies Patchstack, Hexastrike, and WatchTowr have warned that hackers are exploiting the vulnerabilities in the wild, taking over websites still running susceptible versions. The vulnerable versions are WordPress 6.9.0 through 6.9.4 and 7.0.0 to 7.0.1. WordPress’ official stats show over 400 million websites run these flawed versions, though this may not reflect recent patches. Cybersecurity consultant Daniel Card estimated that less than 15% of a sample of 4,200 WordPress websites are vulnerable, projecting around 90 million sites at risk. One critical bug, found by Adam Kues of Searchlight Cyber and dubbed WP2Shell, paired with another bug allows hackers full remote control of vulnerable websites. Automattic and WordPress.org did not respond to a request for comment.
What’s reported
Open questions
Key figures
Sources: TechCrunch
