Websites running affected WordPress versions are facing active exploitation after attackers began targeting two critical security flaws in the wild
WordPress Vulnerabilities Under Active Attack
The issue involves critical flaws affecting WordPress versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1
Despite these automated safeguards, cybersecurity companies including Patchstack, Hexastrike, and WatchTowr detected malicious actors actively exploiting the vulnerabilities
Exposure and Protection Measures
WordPress powers hundreds of millions of websites globally, but the exact number of affected installations remains unclear
Several measures helped limit potential impact:
Automatic Updates: WordPress pushed forced updates where technically feasible
. Security Measures: Some infrastructure providers, including Cloudflare, reported blocking exploit attempts targeting the vulnerabilities
. Web Firewalls: Security tools helped provide additional protection for unpatched environments
.
Automattic spokesperson Megan Fox stated that all platforms managed by the company—including WordPress.com, Pressable, WPVIP, and WP.cloud partners—were protected before public disclosure and received immediate code updates upon release
Source:
TechCrunch — "Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk" (July 20, 2026)
.
.png)
0 Comments