Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk

Hackers are actively exploiting critical vulnerabilities in recent versions of WordPress, potentially affecting millions of websites. Security firms have warned that despite available patches, a significant number of sites remain susceptible to takeover.
Why it matters
WordPress powers a massive portion of the internet; unpatched vulnerabilities pose a significant risk to data security and website integrity for millions of users.
Hackers are breaking into websites that run vulnerable versions of the popular blogging software WordPress, according to several cybersecurity firms. One estimate puts the number of vulnerable WordPress websites at tens of millions as of Monday.
Last week, WordPress patched two critical security flaws , urging people who run its software on their websites to update it “immediately.” The vulnerabilities are so severe that WordPress enabled forced updates where possible. Since then, cybersecurity companies Patchstack, Hexastrike, and WatchTowr have all warned that hackers are exploiting the vulnerabilities in the wild, meaning they are taking over websites that are still running susceptible versions of WordPress.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in