mimile
mimile.ai
Back to feed
This event is part of a larger story
Утечка данных Suno: 55 млн пользователей под угрозой
Read briefing

Hackers exploit patched WordPress bugs, 90M sites at risk

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

Hackers exploit patched WordPress bugs, 90M sites at risk

Hackers are actively exploiting two critical security flaws in WordPress, patched last week, according to multiple cybersecurity firms. An estimated 90 million websites running vulnerable versions remain at risk. The bugs allow full remote control of affected sites.

The Vulnerabilities

WordPress patched two critical flaws on July 13, enabling forced automatic updates where possible. The bugs affect versions 6.9.0 through 6.9.4 and 7.0.0 to 7.0.1. One flaw, dubbed WP2Shell, was reported by Adam Kues of Searchlight Cyber. Combined, the vulnerabilities allow attackers to take full remote control of vulnerable websites.

Exploitation in the Wild

Cybersecurity firms Patchstack, Hexastrike, and WatchTowr have confirmed active exploitation. Daniel Card, a cybersecurity consultant, analyzed a sample of 4,200 WordPress sites and estimated fewer than 15% remain vulnerable. Applying this to the 400 million total WordPress sites, roughly 90 million are still at risk. Cloudflare has been blocking some attacks, and web firewalls offer limited protection.

Response and Impact

WordPress.org and Automattic did not respond to requests for comment. The forced updates have reduced the attack surface, but many sites remain unpatched. The exact number of compromised sites is unknown. Researchers credit WordPress for pushing automatic updates and Cloudflare for mitigating some attacks.

What's Next

WordPress is expected to continue forced updates for remaining vulnerable sites. It remains unclear how many sites have been compromised or when all users will apply the patches.

1 source

Hackers exploit patched WordPress bugs, 90M sites at risk