Free to browse — sign up to save progress & learn live with a tutor.Get started Are you a tutor? Earn by teaching →
Hackers Target WordPress Websites After Security Flaws Found
Daily NewstechnologyTechCrunch

Hackers Target WordPress Websites After Security Flaws Found

B1en25 min

What you'll learn

  • Read and understand a current news story in English.
  • Use six news-related vocabulary words in context.
  • Discuss opinions and predictions about a real-world topic.

Tips for this lesson

  • Read once for the main idea before checking vocabulary.
  • Use the discussion questions to practice giving reasons.
  • Open the source link after class if you want more context.
Step 1 of 4
1Vocabulary

Vocabulary

Study these key words before reading — you'll meet them in the article.

  • vulnerable
    /ˈvʌlnərəbl/
    adjective
    The vulnerable software needs to be updated immediately.
    Daily News vocabulary
  • exploit
    /ɪkˈsplɔɪt/
    verb
    Hackers try to exploit security flaws in software.
    Daily News vocabulary
  • security
    /sɪˈkjʊərəti/
    noun
    The company invests in security to protect its data.
    Daily News vocabulary
  • update
    /ˈʌpdeɪt/
    verb
    It is important to update your software regularly.
    Daily News vocabulary
  • estimate
    /ˈɛstɪmeɪt/
    noun
    The estimate showed that many websites were still at risk.
    Daily News vocabulary
  • control
    /kənˈtroʊl/
    verb
    Hackers can control vulnerable websites if not protected.
    Daily News vocabulary
Step 2 of 4
2Reading

Article

Read the article, then answer the comprehension questions.

Article
Photo: WordPress Foundation (GPL) via Wikimedia Commons

Recently, hackers have been exploiting security flaws in WordPress, a popular blogging software. Cybersecurity firms report that millions of websites are at risk due to these vulnerabilities. Last week, WordPress released updates to fix two serious security issues, urging users to update their sites immediately. Some estimates suggest that tens of millions of WordPress websites are still running vulnerable versions of the software.

The vulnerable versions of WordPress are 6.9.0 through 6.9.4 and 7.0.0 to 7.0.1. According to WordPress statistics, there are over 400 million websites using these flawed versions. However, a cybersecurity consultant, Daniel Card, estimates that less than 15% of these websites are actually vulnerable. Even with this estimate, that could mean around 90 million websites are still at risk. WordPress has implemented automatic updates to help protect users, and companies like Cloudflare are blocking attacks on vulnerable sites.

One of the critical bugs, named WP2Shell, allows hackers to gain full control of affected websites. The company Automattic, which manages WordPress.com, stated that all its hosted sites were protected before the updates were released. They quickly deployed the necessary updates across millions of sites. As the situation develops, it is important for website owners to stay informed and ensure their WordPress installations are up to date to avoid potential attacks.

Comprehension

  1. 1.What software are hackers exploiting?

  2. 2.How many websites are estimated to be vulnerable?

  3. 3.What are the versions of WordPress that have vulnerabilities?

  4. 4.What is one of the critical bugs mentioned in the article?

  5. 5.What did Automattic do to protect its hosted sites?

Step 3 of 4
3Speak freely

Discussion

Share your opinions and experiences with your tutor.

  1. 1.Have you ever experienced a security issue with your website?
  2. 2.What steps do you take to protect your online information?
  3. 3.Do you think automatic updates are effective for security?
  4. 4.How important is it to keep software updated?
  5. 5.What do you think about the role of cybersecurity companies?
Step 4 of 4
4Speak freely

Further Discussion

Think more deeply about the topic and explain your reasons.

  1. 1.How can individuals and businesses better protect themselves online?
  2. 2.What are the ethical responsibilities of software developers regarding security?
  3. 3.In what ways can society improve its overall cybersecurity awareness?