Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk

3 weeks ago 32
stylized WordPress logoImage Credits:TechCrunch

8:35 AM PDT · July 20, 2026

Hackers are breaking into websites that tally susceptible versions of the fashionable blogging bundle WordPress, according to respective cybersecurity firms. One estimation puts the fig of susceptible WordPress websites astatine tens of millions arsenic of Monday.

Last week, WordPress patched 2 captious information flaws, urging radical who tally its bundle connected their websites to update it “immediately.” The vulnerabilities are truthful terrible that WordPress enabled forced updates wherever possible. Since then, cybersecurity companies Patchstack, Hexastrike, and WatchTowr have each warned that hackers are exploiting the vulnerabilities successful the wild, meaning they are taking implicit websites that are inactive moving susceptible versions of WordPress. 

It’s unclear however galore WordPress-powered websites connected the net are astatine risk, but it’s imaginable to marque immoderate educated guesses. The susceptible versions of WordPress are 6.9.0 done 6.9.4, and 7.0.0 to 7.0.1. According to WordPress’ authoritative stats, determination are much than 400 cardinal websites that tally those flawed versions, though these statistic apt don’t bespeak websites that person precocious been patched.

Cybersecurity advisor Daniel Card, who told TechCrunch that helium looked astatine a illustration of astir 4,200 WordPress websites, estimates that less than 15% are vulnerable. Applying Card’s projection crossed the total population of WordPress websites connected the internet, the full fig would inactive beryllium astir 90 million.

The researcher credited WordPress with pushing automatic updates, Cloudflare with blocking attacks against susceptible websites, and websites utilizing cybersecurity protections specified arsenic web firewalls for the constricted fig of sites that could presently beryllium hacked. 

Automattic, arsenic good arsenic WordPress.org, the task that develops WordPress’ open-source code, did not instantly respond to a petition for comment. 

One of the captious WordPress bugs was recovered and reported by Adam Kues of cybersecurity steadfast Searchlight Cyber, which dubbed it WP2Shell. Paired with the different bug, hackers tin instrumentality afloat distant power of susceptible websites.

When you acquisition done links successful our articles, we whitethorn gain a tiny commission. This doesn’t impact our editorial independence.

Lorenzo Franceschi-Bicchierai is simply a Senior Writer astatine TechCrunch, wherever helium covers hacking, cybersecurity, surveillance, and privacy.

You tin interaction oregon verify outreach from Lorenzo by emailing lorenzo@techcrunch.com, via encrypted connection astatine +1 917 257 1382 connected Signal, and @lorenzofb connected Keybase/Telegram.

Read Entire Article