Investing

Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk

1 Mins read

Millions of websites are currently facing a significant security threat as hackers begin exploiting two critical vulnerabilities within the WordPress ecosystem. Despite recent patches released by the software developers, cybersecurity firms including Patchstack, Hexastrike, and WatchTowr report that attackers are actively targeting sites that have failed to update. The flaws are severe enough that WordPress took the unusual step of enabling forced updates wherever possible to protect users from immediate harm.

The scale of the potential crisis is staggering given that hundreds of millions of websites rely on the affected versions of the software. While official statistics suggest an enormous pool of vulnerable installations, industry experts believe the actual number may be lower due to automatic updates and protective measures like web firewalls. Cybersecurity consultant Daniel Card suggests that perhaps only fifteen percent of sites remain susceptible, though even that conservative estimate leaves roughly ninety million websites exposed to attack.

One of the most dangerous aspects of this breach involves a specific flaw dubbed WP2Shell, discovered by researcher Adam Kues. When paired with another existing bug, this vulnerability allows malicious actors to gain full remote control over a targeted website. This level of access gives hackers total authority over site content and data, making it imperative for any administrator still running outdated versions to apply the latest security patches without delay.

Power your team with InHype
[mc4wp_form id="17"]

Add some text to explain benefits of subscripton on your services.