2 min read

WordPress bugs are now under attack at scale

Hackers are exploiting two newly patched WordPress flaws, with estimates suggesting around 90 million sites may still be vulnerable.

Image: TechCrunch

Hackers are actively exploiting two recently patched WordPress security flaws, according to Patchstack, Hexastrike, and WatchTowr. The bugs were fixed last week, and WordPress urged site owners to update immediately — even enabling forced updates where possible because of the severity of the issue.

The vulnerable versions are WordPress 6.9.0 through 6.9.4 and 7.0.0 to 7.0.1. According to WordPress' official statistics, more than 400 million websites run those affected versions, though that figure likely includes sites that have already been patched.

A lower-end estimate from cybersecurity consultant Daniel Card, who told TechCrunch he examined a sample of around 3,500 WordPress websites, suggests that less than 15% remain vulnerable. Even using that projection across the broader WordPress ecosystem would leave roughly 90 million websites exposed.

Recommended reading

2 Million Cars May Hide a Hackable KARR Device

Card told TechCrunch that the number of still-hackable sites is being limited by several factors: WordPress' automatic updates, Cloudflare blocking attacks, and websites using protections such as web application firewalls.

One of the two critical bugs was discovered and reported by Adam Kues of Searchlight Cyber, which named it WP2Shell. Combined with the second flaw, the bugs can give attackers full remote control of vulnerable websites.

WordPress.org did not immediately respond to TechCrunch’s request for comment. Megan Fox, a spokesperson for Automattic, said the company had already protected its hosted platforms before the public release of the fix.

“All sites hosted by Automattic, including WordPress.com, Pressable, WPVIP, and WP.cloud partners, were protected even before the release. When the code updates were published, we deployed them immediately across millions of sites.”

Megan Fox, spokesperson for Automattic
Sophia Reynolds

Security Editor

Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.

via TechCrunch

// Keep reading