Hackers are breaking into websites running vulnerable versions of the popular WordPress blogging software, according to several cybersecurity companies. One estimate puts the number of vulnerable WordPress websites in the tens of millions as of Monday. Last week, WordPress fixed two critical security flaws, urging people who run its software on their websites to update
Hackers are breaking into websites running vulnerable versions of the popular WordPress blogging software, according to several cybersecurity companies. One estimate puts the number of vulnerable WordPress websites in the tens of millions as of Monday.
Last week, WordPress fixed two critical security flaws, urging people who run its software on their websites to update it “immediately.” The vulnerabilities are so severe that WordPress enabled forced updates whenever possible. Since then, cybersecurity companies Patchstack, Hexastrike, and WatchTowr have warned that hackers are exploiting vulnerabilities in the wild, meaning they are taking control of websites still running susceptible versions of WordPress.
It’s unclear how many WordPress-based websites on the Internet are at risk, but it’s possible to make some educated guesses. Vulnerable WordPress versions are 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1. According to official WordPress statistics, there are over 400 million websites running those faulty versions, although these statistics likely do not reflect websites that have been recently patched.
Cybersecurity consultant Daniel Card, who told TechCrunch he analyzed a sample of about 4,200 WordPress websites, estimates that fewer than 15% are vulnerable. Applying Card’s projection to the total population of WordPress websites on the Internet, the total figure would still be around 90 million.
The researcher credited WordPress for pushing automatic updates, Cloudflare for blocking attacks against vulnerable websites, and websites using cybersecurity protections, such as web firewalls, for the limited number of sites that could currently be hacked.
Automattic, as well as WordPress.org, the project that develops the WordPress open source code, did not immediately respond to a request for comment.
One of the critical WordPress bugs was found and reported by Adam Kues of cybersecurity firm Searchlight Cyber, who dubbed it WP2Shell. Along with the other bug, hackers can take full remote control of vulnerable websites.
When you buy through links in our articles, we may earn a small commission. This does not affect our editorial independence.
For more tech updates, stay tuned to our blog.

















