Hackers are taking advantage of newly fixed WordPress vulnerabilities, endangering millions of sites.

Hackers are taking advantage of newly fixed WordPress vulnerabilities, endangering millions of sites.

Cybersecurity firms report that hackers are infiltrating websites running weak versions of the widely used blogging platform WordPress. An estimation suggests that the count of at-risk WordPress sites is in the tens of millions as of Monday.

Recently, WordPress addressed two major security vulnerabilities, urging website operators to upgrade their software “immediately.” The seriousness of these flaws led to WordPress implementing mandatory updates where feasible. Following this, cybersecurity agencies such as Patchstack, Hexastrike, and WatchTowr have cautioned that attackers are taking advantage of the vulnerabilities, actively compromising sites that have yet to update from compromised versions of WordPress. 

While the exact number of WordPress-based sites at risk remains uncertain, educated estimates can be made. The compromised versions of WordPress include 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1. As per WordPress’ official data, there are upwards of 400 million sites operating on those flawed versions, though these figures likely don’t account for recently updated websites.

Cybersecurity expert Daniel Card, who analyzed a sample of about 3,500 WordPress sites, assesses that under 15% are at risk. If Card’s estimate is applied to the broader base of WordPress sites on the internet, the total could still reach around 90 million.

The researcher lauded WordPress for implementing auto-updates, Cloudflare for stopping attacks on at-risk sites, and sites leveraging cybersecurity measures like web firewalls for the minimal number of sites currently vulnerable to hacks. 

WordPress.org, the organization behind the development of WordPress’ open source code, did not swiftly reply to a request for comments. Megan Fox, spokesperson for Automattic, the firm responsible for WordPress.com and its contributions to the open-source initiative, informed TechCrunch that “all sites hosted by Automattic, including WordPress.com, Pressable, WPVIP, and WP.cloud partners, were secured prior to the release. When the code updates became available, we rolled them out immediately across millions of sites.”

One of the significant WordPress vulnerabilities was discovered and reported by Adam Kues of the cybersecurity company Searchlight Cyber, which named it WP2Shell. Along with the other flaw, hackers can gain complete remote access to at-risk websites.

When you make a purchase through links in our stories, we might receive a small commission. This does not impact our editorial independence.

Leave a Reply