Hackers are attacking websites using vulnerable versions of WordPress, according to several cybersecurity firms. One estimate put the number of vulnerable WordPress sites in the tens of millions as of Monday.
Last week, WordPress fixed two critical security vulnerabilities, urging users who use its software on their websites to update it “immediately.” The security flaws are so serious that WordPress has enabled forced updates where possible.
Since then, cybersecurity firms Patchstack, Hexastrike, and WatchTowr have warned that hackers are exploiting the vulnerabilities, taking over websites that are still running vulnerable versions of WordPress.
It is not known how many WordPress websites are at risk online, but it is possible to make some guesses. The vulnerable WordPress versions are 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1.
According to official WordPress statistics, there are over 400 million websites running these flawed versions, although these statistics likely do not reflect sites that have been recently patched.
One of the critical WordPress bugs was discovered and reported by Adam Kues of cybersecurity firm Searchlight Cyber, which called it WP2ShellCombined with the other flaw, hackers can gain complete remote control over vulnerable websites.
Versions Affected
| <6.9.0 | not affected |
| 6.9.0 - 6.9.4 | affected, fixed in 6.9.5 |
| 7.0.0 - 7.0.1 | affected, fixed in 7.0.2 |
Although the press releases will range from very select to rare, I said I'd pass...because sometimes the editors hide.


