READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Hackers Are Actively Exploiting Two Critical WordPress Flaws, Up to 90 Million Sites at Risk

Hackers Are Actively Exploiting Two Critical WordPress Flaws, Up to 90 Million Sites at Risk
WordPress patched two severe security bugs last week and told site owners to update immediately. Cybersecurity firms Patchstack, Hexastrike, and WatchTowr now say hackers are already exploiting the flaws in the wild, and researchers estimate tens of millions of sites remain vulnerable.

WordPress runs a huge chunk of the internet. Last week, WordPress pushed patches for two critical security flaws in its software, according to TechCrunch. The bugs were serious enough that WordPress enabled forced automatic updates where possible and told site owners to patch "immediately."

Since the patch went out, cybersecurity firms Patchstack, Hexastrike, and WatchTowr have all reported hackers are actively exploiting the vulnerabilities, breaking into websites still running the outdated, susceptible versions.

How Bad Is It

The vulnerable versions are WordPress 6.9.0 through 6.9.4, and 7.0.0 through 7.0.1. WordPress's own statistics show more than 400 million websites running those flawed versions, though that figure likely hasn't caught up with sites that already patched.

A more realistic estimate comes from cybersecurity consultant Daniel Card, who told TechCrunch he sampled roughly 4,200 WordPress sites and found less than 15% still vulnerable. Apply that percentage across the full population of WordPress sites, and you land around 90 million vulnerable websites as of Monday, July 20.

It's a massive attack surface. The figure is an estimate, not a hard count. Nobody, including WordPress itself, has published an exact number of sites currently exploitable.

How the Attack Works

One of the two bugs was discovered and reported by Adam Kues of cybersecurity firm Searchlight Cyber, which named it WP2Shell. On its own, it's dangerous. Paired with the second flaw WordPress patched, hackers can take full remote control of a vulnerable site, according to TechCrunch's reporting.

Full remote control means an attacker isn't just defacing a page. They can install malware, steal user data, redirect visitors to scam sites, or turn the compromised server into a launchpad for attacks elsewhere. For small businesses, bloggers, and nonprofits running WordPress without dedicated IT staff, that's the kind of breach that can take a site offline for good.

What's Actually Slowing This Down

Card credited three things with limiting the damage so far: WordPress pushing automatic updates instead of waiting on site owners to act, Cloudflare blocking attack traffic against known-vulnerable sites, and site owners who already run web application firewalls. Automatic forced updates are exactly the kind of decisive move that prevents a bad bug from turning into a catastrophe. WordPress didn't sit on this. It patched fast and pushed the fix hard.

But automatic updates don't reach everyone. Sites running heavily customized installations, outdated hosting environments, or configurations where auto-updates are disabled are still sitting ducks. That's the gap attackers are working right now.

What's Missing From the Coverage

TechCrunch's reporting is solid on the technical details but light on accountability specifics. Automattic, the company behind WordPress.org's commercial arm, and WordPress.org itself did not respond to TechCrunch's request for comment. Site owners deserve to know whether WordPress has a running tally of how many sites remain compromised, not just estimates from outside researchers.

There's also no indication yet of who's behind these attacks, whether it's opportunistic criminal groups, ransomware operators, or something more organized. No attribution has been made public.

What Site Owners Should Do Now

If you run a WordPress site and haven't confirmed you're on version 6.9.5, 7.0.2, or later, check today. Don't assume auto-update handled it. Log into the dashboard and verify the version number directly.

If your site was compromised before you patched, updating alone won't fix it. Security firms including Patchstack have warned that attackers who already gained remote control can leave backdoors behind that survive a version update. Anyone running an affected version between the patch release and today should assume compromise is possible and scan for unauthorized admin accounts, unfamiliar plugins, or unexpected file changes.

No government agency has issued a public advisory on this specific incident as of Monday. Whether the Cybersecurity and Infrastructure Security Agency or similar bodies step in with guidance for federal contractors or critical infrastructure sites running WordPress remains unclear.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center-left
TechCrunchHackers are exploiting recently patched WordPress bugs, putting millions of websites at risk