Hackers are actively breaking into websites running outdated versions of WordPress, following the discovery and public disclosure of two critical security flaws that together allow attackers to take full remote control of a vulnerable site.
WordPress patched both vulnerabilities last week, urging site administrators to update immediately and enabling forced updates where possible. The flaws affect versions 6.9.0 through 6.9.4, and 7.0.0 through 7.0.1. According to WordPress's own statistics, more than 400 million websites run those affected versions, though that figure does not account for sites that have already been patched since the disclosure.
Cybersecurity companies Patchstack, Hexastrike, and WatchTowr have all confirmed active exploitation in the wild. Cybersecurity consultant Daniel Card, who examined a sample of approximately 4,200 WordPress websites, estimated that under 15% remained unpatched. Extrapolated across the total number of WordPress sites on the internet, that figure would still represent approximately 90 million vulnerable websites.
One of the two bugs, dubbed WP2Shell and discovered by Adam Kues of Searchlight Cyber, enables remote shell access when paired with the second vulnerability. The researcher credited WordPress for pushing automatic updates, Cloudflare for blocking attacks against unpatched sites, and web application firewalls for limiting successful breaches.