Hackers are breaking into websites running vulnerable versions of the popular blogging software WordPress, according to multiple cybersecurity companies. Some estimates put the number of vulnerable WordPress websites in the tens of millions as of Monday.
Last week, WordPress patched two major security flaws and urged people running the software on their websites to update “immediately.” This vulnerability is so serious that WordPress enabled forced updates whenever possible. Since then, cybersecurity firms Patchstack, Hexastrike, and WatchTowr have all warned that hackers are exploiting the vulnerability to take over websites that are still running vulnerable versions of WordPress.
It's unclear how exposed WordPress-powered websites are on the internet, but we can make some educated guesses. The vulnerable WordPress versions are 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1. According to official WordPress statistics, there are over 400 million websites running these flawed versions, but these statistics may not reflect recently patched websites.
Cybersecurity consultant Daniel Card told TechCrunch that he looked at a sample of about 4,200 WordPress websites and estimated that fewer than 15% were vulnerable. If we apply Card's prediction to the total population of WordPress websites on the internet, the total number still stands at about 90 million.
Researchers credited WordPress for promoting automatic updates, Cloudflare for blocking attacks on vulnerable websites, and using cybersecurity protections such as web firewalls for the limited number of sites where websites can currently be hacked.
Automattic and WordPress.org, the project that develops WordPress open source code, did not immediately respond to requests for comment.
One of the major bugs in WordPress was discovered and reported by Adam Kues of the cybersecurity firm Searchlight Cyber and was named WP2Shell. When combined with other bugs, hackers can gain complete remote control of vulnerable websites.
If you buy through links in our articles, we may earn a small commission. This does not affect editorial independence.

