Hackers exploit patched WordPress bugs, millions of sites at risk

Hackers exploit patched WordPress bugs, millions of sites at risk

8 reported1 unconfirmed

According to cybersecurity firms, hackers are breaking into websites running vulnerable versions of WordPress. Last week, WordPress patched two critical security flaws and urged users to update immediately, enabling forced updates where possible. Cybersecurity companies Patchstack, Hexastrike, and WatchTowr have warned that hackers are exploiting the vulnerabilities in the wild, taking over websites still running susceptible versions. The vulnerable versions are WordPress 6.9.0 through 6.9.4 and 7.0.0 to 7.0.1. WordPress’ official stats show over 400 million websites run these flawed versions, though this may not reflect recent patches. Cybersecurity consultant Daniel Card estimated that less than 15% of a sample of 4,200 WordPress websites are vulnerable, projecting around 90 million sites at risk. One critical bug, found by Adam Kues of Searchlight Cyber and dubbed WP2Shell, paired with another bug allows hackers full remote control of vulnerable websites. Automattic and WordPress.org did not respond to a request for comment.

What’s reported

Hackers are exploiting two recently patched critical WordPress security flaws.
Vulnerable versions include WordPress 6.9.0 through 6.9.4 and 7.0.0 to 7.0.1.
WordPress enabled forced updates where possible after patching the flaws.
Cybersecurity firms Patchstack, Hexastrike, and WatchTowr warned of active exploitation.
WordPress’ official stats indicate over 400 million websites run flawed versions.
Cybersecurity consultant Daniel Card estimated less than 15% of a 4,200-site sample are vulnerable, projecting around 90 million sites at risk.
One bug, WP2Shell, was found by Adam Kues of Searchlight Cyber and allows full remote control when paired with the other bug.
Automattic and WordPress.org did not respond to a request for comment.

Open questions

The exact number of websites currently compromised is not provided in the source article.

Key figures

Daniel Card, cybersecurity consultant
Adam Kues, cybersecurity firm Searchlight Cyber
Patchstack, cybersecurity firm
Hexastrike, cybersecurity firm
WatchTowr, cybersecurity firm
Automattic (did not respond)
WordPress.org (did not respond)

Sources: TechCrunch

You may also like...

Leave a Reply

Your email address will not be published. Required fields are marked *