Hackers exploiting recently - ```json "title": "wordpress vulnerabilities million

Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk

“`json
{
“title”: “WordPress Vulnerabilities Put 90 Million Websites at Risk”,
“slug”: “wordpress-vulnerabilities-90-million-websites-at-risk”,
“meta_description”: “Critical WordPress security flaws affect millions of sites. Hackers actively exploit vulnerabilities in versions 6.9.0-6.9.4 and 7.0.0-7.0.1.”,
“keywords”: [“WordPress vulnerabilities”, “WordPress security”, “website security”, “WordPress hack”, “cybersecurity”],
“primary_keyword”: “WordPress vulnerabilities”,
“content”: “

Hackers are actively exploiting critical security flaws in WordPress, targeting websites that haven’t updated to the latest version. Multiple cybersecurity firms confirmed that attackers are breaking into vulnerable sites, raising concerns about millions of potentially compromised websites.

WordPress released emergency patches last week to address two severe security vulnerabilities. The organization urged website administrators to update immediately. The flaws proved serious enough that WordPress enabled forced automatic updates wherever technically possible.

Scale of Vulnerable WordPress Websites

The affected WordPress versions include 6.9.0 through 6.9.4 and 7.0.0 to 7.0.1. Official WordPress statistics show over 400 million websites running these versions. However, these numbers likely include sites that have already applied security patches.

Cybersecurity consultant Daniel Card analyzed approximately 3,500 WordPress websites to assess the actual risk. His research indicates that fewer than 15% remain vulnerable to attack. When applied to the total WordPress user base, this percentage suggests around 90 million websites could still be at risk.

Card credited several factors for limiting the number of vulnerable sites. WordPress pushed automatic updates to many installations. Additionally, Cloudflare blocked attacks against susceptible websites. Web firewalls and other cybersecurity protections also helped shield many sites from exploitation.

Active Exploitation in the Wild

Three cybersecurity firms—Patchstack, Hexastrike, and WatchTowr—issued warnings about active exploitation. The companies confirmed that hackers are taking over websites running unpatched WordPress versions. This type of “in the wild” exploitation indicates immediate and ongoing danger.

The security flaws allow attackers to gain complete remote control of vulnerable websites. Researchers from Searchlight Cyber discovered one of the critical bugs. The firm named the vulnerability WP2Shell. When paired with the second bug, hackers can fully compromise affected sites.

WordPress Response and Protection Measures

Megan Fox, spokesperson for Automattic, confirmed protective measures for company-hosted sites. Automattic operates WordPress.com and contributes to the open source WordPress project. All sites hosted by Automattic received protection before the vulnerability disclosure.

Fox stated that the company deployed code updates immediately after publication. The patches covered millions of sites across WordPress.com, Pressable, WPVIP, and WP.cloud partners. This rapid response helped prevent widespread exploitation on managed hosting platforms.

WordPress.org, which develops the open source WordPress code, has not yet commented on the security incident. The organization typically maintains a policy of limited public statements during active security situations.

What Website Owners Should Do

Website administrators should verify their WordPress installation is running the latest version. The current secure releases address both critical vulnerabilities. Sites that disabled automatic updates face the highest risk of compromise.

Security experts recommend checking WordPress version numbers immediately. Administrators should also review their sites for signs of unauthorized access. Unusual files, modified code, or unexpected user accounts may indicate a successful breach.

Organizations using managed WordPress hosting likely received automatic protection. However, self-hosted WordPress installations require manual verification and updating. The security patches are available through the standard WordPress update mechanism.

“,
“excerpt”: “Critical WordPress security flaws affect an estimated 90 million websites. Hackers are actively exploiting vulnerabilities in versions 6.9.0-6.9.4 and 7.0.0-7.0.1, allowing complete remote control of unpatched sites.”,
“image_alt_suggestion”: “WordPress logo with security lock symbol showing cybersecurity vulnerability alert”,
“internal_link_suggestions”: [“website security best practices”, “WordPress maintenance guide”, “protecting your website from hackers”]
}
“`

Original Source: techcrunch.com

Leave a Comment





This site uses Akismet to reduce spam. Learn how your comment data is processed.