Hackers are actively breaking into websites running vulnerable versions of WordPress, according to warnings from several cybersecurity firms.
WordPress patched two critical security flaws last week and urged website owners to update immediately. The bugs were considered severe enough that WordPress enabled forced updates where possible.
Cybersecurity firms Patchstack, Hexastrike, and WatchTowr have warned that attackers are now exploiting the flaws in the wild. This means hackers are not just testing the bugs. They are using them to compromise websites that have not yet been updated.
The affected versions include WordPress 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1.
The exact number of vulnerable WordPress websites is unclear.
WordPress’ official statistics show more than 400 million websites running the affected versions. However, that figure may include sites that have already received the latest security updates.
Cybersecurity consultant Daniel Card told TechCrunch that he reviewed a sample of around 3,500 WordPress websites and estimated that less than 15 percent were still vulnerable.
Even with that lower estimate, the total number of exposed websites could still be around 90 million.
Card said the number of hackable sites may have been reduced by several protections.
He credited WordPress for pushing automatic updates, Cloudflare for blocking attacks against vulnerable websites, and web security tools such as firewalls for helping protect some site owners.
However, websites that have not updated or do not have proper protections remain at risk.
WordPress.org, which develops the open-source WordPress software, did not immediately respond to TechCrunch’s request for comment.
Automattic spokesperson Megan Fox said all sites hosted by Automattic, including WordPress.com, Pressable, WPVIP, and WP.cloud partners, were already protected before the public release.
She added that Automattic deployed the updates across millions of hosted sites as soon as the patches were published.
One of the critical flaws was discovered and reported by Adam Kues of cybersecurity firm Searchlight Cyber.
The company has named the bug WP2Shell.
When combined with the second vulnerability, the flaw can allow hackers to take full remote control of vulnerable WordPress websites.
Anyone running a WordPress website should check their version and install the latest update immediately.
Site owners should also review admin accounts, website files, server logs, and security alerts for signs of compromise, especially if their site was running one of the affected versions after the patches were released.
Get the latest tech news, telecom insights, and product launches wherever you prefer.
Add ProPakistani to Preferred Sources and see more of our stories in Google Search and Top Stories.