Hackers are exploiting recently patched critical vulnerabilities in WordPress, giving them a path to remotely compromise websites that have not yet been updated, multiple cybersecurity reports say. WordPress last week releases fixes for two security flaws and urges users to update “immediately,” including enabling forced updates where possible. Researchers and security firms report that attackers are actively using the vulnerabilities against internet-facing WordPress installations still running susceptible versions.
The outlets describe the scope of exposure in terms of vulnerable version ranges (WordPress 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1). One cited estimate, based on sampling by consultant Daniel Card, suggests fewer than 15% of checked sites remain vulnerable; applying that proportion to broader WordPress statistics implies a total on the order of tens of millions of websites. Separate figures from WordPress’ own version reporting are cited as potentially overstating risk because they may not reflect recent patching.
One of the flaws is identified as being related to “WP2Shell,” and, when combined with the other vulnerability, is described as enabling full remote takeover of affected sites.