Recently, hackers have been exploiting security flaws in WordPress, a popular blogging software. Cybersecurity firms report that millions of websites are at risk due to these vulnerabilities. Last week, WordPress released updates to fix two serious security issues, urging users to update their sites immediately. Some estimates suggest that tens of millions of WordPress websites are still running vulnerable versions of the software.
The vulnerable versions of WordPress are 6.9.0 through 6.9.4 and 7.0.0 to 7.0.1. According to WordPress statistics, there are over 400 million websites using these flawed versions. However, a cybersecurity consultant, Daniel Card, estimates that less than 15% of these websites are actually vulnerable. Even with this estimate, that could mean around 90 million websites are still at risk. WordPress has implemented automatic updates to help protect users, and companies like Cloudflare are blocking attacks on vulnerable sites.
One of the critical bugs, named WP2Shell, allows hackers to gain full control of affected websites. The company Automattic, which manages WordPress.com, stated that all its hosted sites were protected before the updates were released. They quickly deployed the necessary updates across millions of sites. As the situation develops, it is important for website owners to stay informed and ensure their WordPress installations are up to date to avoid potential attacks.
