The vulnerabilities affect WordPress versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. While official statistics suggest over 400 million sites run these versions, current patching rates remain difficult to quantify. Cybersecurity consultant Daniel Card analyzed a sample of 4,200 sites and projected that roughly 15% remain exposed. If accurate, this estimate implies that approximately 90 million websites could still be vulnerable to remote takeover.
Researchers at Searchlight Cyber identified one of the primary flaws, dubbed WP2Shell by analyst Adam Kues. When combined with a second critical vulnerability, the exploit allows unauthorized users to gain full remote control over affected servers. While Cloudflare and various web firewalls have begun blocking incoming attacks, the sheer scale of the WordPress ecosystem leaves a massive surface area for exploitation. Automattic and the WordPress.org development team have not commented on the ongoing incident.

Comments (0)
No comments yet. Be the first!