Last week, WordPress patched two critical security vulnerabilities and urged website owners to update immediately. Due to the severity of the issues, the platform also enabled forced updates where feasible. However, several security firms later reported that hackers have already begun exploiting these vulnerabilities to target websites that have not yet been updated.
Multiple security agencies have issued warnings.
Patchstack, Hexastrike, and WatchTowr all reported that the related vulnerabilities have been exploited in real-world attacks. This means that sites still running affected versions could be directly taken over by attackers.
TechCrunch, citing public information, stated that the vulnerable versions include WordPress 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. According to official WordPress statistics, over 400 million websites run these versions. However, this number may not yet reflect sites that have recently been updated.
Sample estimates still point to widespread exposure
After analyzing a sample of approximately 4,200 WordPress websites, cybersecurity consultant Daniel Card estimated that fewer than 15% of websites may still be exposed to risk. Even at this rate, an estimated 90 million websites worldwide could remain vulnerable to attack.
This estimate also shows that although automatic updates have reduced the attack surface, the number of websites that have not completed upgrades remains significant. For sites relying on WordPress to run content, stores, or business pages, the vulnerability window remains open.
Automatic updates and protection tools reduce risk.
Daniel Card believes that the number of websites currently vulnerable to direct attacks is not higher due to WordPress promoting automatic updates, Cloudflare blocking attacks targeting vulnerable sites, and some websites implementing web firewalls and other security measures.
One of the critical vulnerabilities was discovered and reported by Adam Kues, a researcher at Searchlight Cyber, who named it WP2Shell. The report states that if this vulnerability is used in conjunction with another, attackers can gain full remote control over affected websites.
