Key Takeaways
- WordPress patched two critical security flaws last week.
- Cybersecurity firms warn attackers are exploiting the bugs in the wild.
- Website owners should update immediately to protect their sites.
Hackers are actively targeting websites running vulnerable versions of WordPress, according to warnings from several cybersecurity firms. The software giant patched two critical security flaws last week and urged website owners to update immediately to mitigate the risk.
The affected versions include WordPress 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1, with millions of sites potentially still exposed. Cybersecurity consultant Daniel Card told TechCrunch that he reviewed a sample of around 3,500 WordPress websites and estimated less than 15 percent were still vulnerable.
Even with this lower estimate, the total number of exposed websites could still be around 90 million. Automattic spokesperson Megan Fox said all sites hosted by Automattic, including WordPress.com, Pressable, WPVIP, and WP.cloud partners, were already protected before the public release. She added that updates were deployed across millions of hosted sites as soon as the patches were published.
One of the critical flaws was discovered and reported by Adam Kues of cybersecurity firm Searchlight Cyber. The company has named the bug WP2Shell. When combined with the second vulnerability, this flaw can allow hackers to take full remote control of vulnerable WordPress websites.
Website owners should check their version and install the latest update immediately. Site owners should also review admin accounts, website files, server logs, and security alerts for signs of compromise, especially if their site was running one of the affected versions after the patches were released.
Automatically updating to the latest version can help reduce the risk. However, websites that have not updated or do not have proper protections remain at risk. Cybersecurity consultant Daniel Card highlighted several protections, including WordPress’ automatic updates, Cloudflare’s blocking mechanisms, and web security tools such as firewalls.
Website owners should update immediately to protect their sites.





