WordPress high-risk vulnerabilities exploited, millions of sites at risk

icon币界网
Share
AI summary iconSummary
Risk-on assets came under renewed pressure as WordPress confirmed two high-severity vulnerabilities affecting versions 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1. Security firms report active exploitation, with over 400 million sites at risk. Experts estimate up to 90 million remain unpatched. Cloudflare and automatic updates are providing some protection, but many sites are still lagging. Risk-off assets saw a temporary rally as investors reassessed their cybersecurity exposure. Immediate action is recommended for site operators.
CoinDesk reports:

Last week, WordPress patched two critical security vulnerabilities and urged website owners to update immediately. Due to the severity of the issues, the platform also enabled forced updates where feasible. However, several security firms later reported that hackers have already begun exploiting these vulnerabilities to target websites that have not yet been updated.

Multiple security agencies have issued warnings.

Patchstack, Hexastrike, and WatchTowr all reported that the related vulnerabilities have been exploited in real-world attacks. This means that sites still running affected versions could be directly taken over by attackers.

TechCrunch, citing public information, stated that the vulnerable versions include WordPress 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. According to official WordPress statistics, over 400 million websites run these versions. However, this number may not yet reflect sites that have recently been updated.

Sample estimates still point to widespread exposure

After analyzing a sample of approximately 4,200 WordPress websites, cybersecurity consultant Daniel Card estimated that fewer than 15% of websites may still be exposed to risk. Even at this rate, an estimated 90 million websites worldwide could remain vulnerable to attack.

This estimate also shows that although automatic updates have reduced the attack surface, the number of websites that have not completed upgrades remains significant. For sites relying on WordPress to run content, stores, or business pages, the vulnerability window remains open.

Automatic updates and protection tools reduce risk.

Daniel Card believes that the number of websites currently vulnerable to direct attacks is not higher due to WordPress promoting automatic updates, Cloudflare blocking attacks targeting vulnerable sites, and some websites implementing web firewalls and other security measures.

One of the critical vulnerabilities was discovered and reported by Adam Kues, a researcher at Searchlight Cyber, who named it WP2Shell. The report states that if this vulnerability is used in conjunction with another, attackers can gain full remote control over affected websites.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.