Skip to content
TechCrunch·

🚨Hackers Exploit WordPress Vulnerabilities on Tens of Millions of Sites

Tens of millions of sites at risk from critical WordPress flaws

TL;DR

Hackers are exploiting critical security vulnerabilities in tens of millions of WordPress websites. Immediate updates urged to prevent full remote control.

Hackers have begun exploiting two critical security flaws in WordPress versions 6.9.0 through 7.0.1, affecting an estimated 90 million sites. This is a major concern for website owners and developers as attackers can gain full remote access. Immediate updates are essential to prevent further damage. The vulnerabilities were patched last week, but less than 15% of affected sites have updated yet.

Hackers Exploit WordPress Vulnerabilities on Tens of Millions of Sites — TechCrunch

Key Points

1

Two critical security flaws in WordPress versions 6.9.0-7.0.1 are being actively exploited by hackers, affecting up to 90 million sites.

2

WordPress has enabled forced updates for the most severe vulnerabilities, but less than 15% of affected websites have updated yet.

3

Cybersecurity firms Patchstack, Hexastrike, and WatchTowr warn that attacks are already underway in the wild, exploiting paired bugs to gain full control.

4

Cloudflare is blocking attack attempts against vulnerable WordPress sites, helping mitigate some of the immediate risks for users.

5

One critical bug dubbed WP2Shell allows hackers to take full remote control over affected websites when combined with another flaw.

Why It Matters

If you manage a WordPress site running versions 6.9.0-7.0.1, your security is compromised until you update immediately. The risk of total control by attackers is real and urgent.

WordPresscybersecurityvulnerabilitiesforced-updatespatching

Frequently Asked Questions

Why does this matter?

If you manage a WordPress site running versions 6.9.0-7.0.1, your security is compromised until you update immediately. The risk of total control by attackers is real and urgent.

What happened?

Hackers are exploiting critical security vulnerabilities in tens of millions of WordPress websites. Immediate updates urged to prevent full remote control.

Comments

Subscribe to join the conversation...

Be the first to comment

Enjoyed this article?

Get it daily. 7am. Free. Reads in 5 minutes.

Also get