Hackers Exploit Critical WordPress Flaws, Putting Millions of Sites at Risk

 

Illustration representing WordPress security vulnerabilities and website protection measures.
Photo Credit: petatech news

Websites running affected WordPress versions are facing active exploitation after attackers began targeting two critical security flaws in the wild. Cybersecurity firms have issued warnings after researchers identified vulnerabilities that could allow remote attackers to gain administrative access to affected installations.

WordPress Vulnerabilities Under Active Attack

The issue involves critical flaws affecting WordPress versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. Following the identification of the bugs, WordPress patched the software and urged administrators to update immediately. WordPress enabled forced automatic updates where technically possible.

Despite these automated safeguards, cybersecurity companies including Patchstack, Hexastrike, and WatchTowr detected malicious actors actively exploiting the vulnerabilities. Adam Kues of cybersecurity firm Searchlight Cyber identified one of the core vulnerabilities—dubbed WP2Shell—which could allow attackers to gain remote administrative access when combined with the second flaw.

Exposure and Protection Measures

WordPress powers hundreds of millions of websites globally, but the exact number of affected installations remains unclear. Cybersecurity consultant Daniel Card analyzed a sample of approximately 3,500 WordPress websites and found that fewer than 15% remained vulnerable in the sample.

Several measures helped limit potential impact:

  • Automatic Updates: WordPress pushed forced updates where technically feasible.

  • Security Measures: Some infrastructure providers, including Cloudflare, reported blocking exploit attempts targeting the vulnerabilities.

  • Web Firewalls: Security tools helped provide additional protection for unpatched environments.

Automattic spokesperson Megan Fox stated that all platforms managed by the company—including WordPress.com, Pressable, WPVIP, and WP.cloud partners—were protected before public disclosure and received immediate code updates upon release. WordPress.org did not immediately respond to requests for comment.

Source:

Post a Comment

0 Comments