Hackers are exploiting two recently patched critical security flaws in WordPress, the world’s most popular blogging software, leaving millions of websites vulnerable to remote takeover. Cybersecurity firms including Patchstack, Hexastrike, and WatchTowr have confirmed active exploitation of these bugs in the wild.
Scope of the Vulnerability
The affected WordPress versions range from 6.9.0 through 6.9.4 and 7.0.0 to 7.0.1. Official WordPress statistics indicate that over 400 million websites run these versions, although many may have already applied the latest security patches. A cybersecurity consultant’s analysis of a sample of 3,500 sites suggests that around 15% remain vulnerable, potentially exposing approximately 90 million websites globally.
Response and Mitigation Efforts
WordPress responded swiftly by releasing forced automatic updates where possible and urging all users to update immediately. Automattic, the company behind WordPress.com, confirmed that all sites hosted on its platforms were protected before the patch release and updates were deployed instantly across millions of sites.
Cloudflare and other cybersecurity providers have been actively blocking attacks targeting vulnerable sites, while web firewalls add an extra layer of protection for those still at risk.
Details of the Exploits
One of the bugs, dubbed WP2Shell by cybersecurity firm Searchlight Cyber, was discovered by researcher Adam Kues. When combined with the second vulnerability, hackers can gain full remote control over affected websites, potentially leading to data breaches, defacement, or other malicious activities.
Website owners are strongly advised to verify their WordPress version and apply updates without delay to mitigate risks. Regular security audits and the use of robust cybersecurity measures are recommended for ongoing protection.
For businesses and developers looking to integrate AI-powered security and workflow automation, JASON AI offers practical solutions to enhance website protection and streamline updates. More information is available at https://jasonjuul.com.
Disclaimer: This article provides an overview of recent cybersecurity vulnerabilities in WordPress and does not offer medical, legal, or professional advice. Readers should consult relevant experts for specific guidance.