Hackers exploit patched WordPress bugs, 90M sites at risk
This digest was compiled by AI from multiple sources — links to the originals are below.

Hackers are actively exploiting two critical security flaws in WordPress, patched last week, according to multiple cybersecurity firms. An estimated 90 million websites running vulnerable versions remain at risk. The bugs allow full remote control of affected sites.
The Vulnerabilities
WordPress patched two critical flaws on July 13, enabling forced automatic updates where possible. The bugs affect versions 6.9.0 through 6.9.4 and 7.0.0 to 7.0.1. One flaw, dubbed WP2Shell, was reported by Adam Kues of Searchlight Cyber. Combined, the vulnerabilities allow attackers to take full remote control of vulnerable websites.
Exploitation in the Wild
Cybersecurity firms Patchstack, Hexastrike, and WatchTowr have confirmed active exploitation. Daniel Card, a cybersecurity consultant, analyzed a sample of 4,200 WordPress sites and estimated fewer than 15% remain vulnerable. Applying this to the 400 million total WordPress sites, roughly 90 million are still at risk. Cloudflare has been blocking some attacks, and web firewalls offer limited protection.
Response and Impact
WordPress.org and Automattic did not respond to requests for comment. The forced updates have reduced the attack surface, but many sites remain unpatched. The exact number of compromised sites is unknown. Researchers credit WordPress for pushing automatic updates and Cloudflare for mitigating some attacks.
What's Next
WordPress is expected to continue forced updates for remaining vulnerable sites. It remains unclear how many sites have been compromised or when all users will apply the patches.
1 source
Hackers exploit patched WordPress bugs, 90M sites at risk






