Hackers Exploit Patched WordPress Bugs, Millions of Sites at Risk

Cybercriminals are actively exploiting two critical WordPress vulnerabilities patched just days ago, putting millions of websites at risk of full takeover.

By Central
Two critical WordPress bugs, including the WP2Shell exploit, are actively attacking unpatched sites worldwide.
Highlights
  • Two critical WordPress vulnerabilities allow attackers to achieve full remote code execution and site takeover.
  • Despite the patch, an estimated 90 million WordPress sites remain potentially exposed to active attacks.
  • Proactive measures like forced automatic updates and WAFs have contained the number of actual breaches.

Hackers are actively exploiting two critical security vulnerabilities in WordPress that were patched last week, putting tens of millions of websites at risk of complete takeover. Cybersecurity firms Patchstack, Hexastrike, and WatchTowr have all confirmed that the flaws are being exploited in the wild, as administrators of vulnerable sites have failed to apply the urgent updates. The situation underscores the persistent danger of unpatched software, even when a fix is readily available and automatically pushed to millions of hosts.

WordPress Bugs Allow Full Remote Code Execution

The two vulnerabilities, which were patched in the WordPress 7.0.2 release, allow attackers to achieve complete remote control of a vulnerable website. One of the flaws, discovered and reported by Adam Kues of Searchlight Cyber and dubbed WP2Shell, enables an attacker to execute arbitrary code on the server. When combined with the second bug, an attacker can bypass all authentication and take full administrative control, effectively owning the site and its data. WordPress rated the flaws as critical and urged all users to update “immediately,” implementing forced automatic updates where possible to staunch the bleeding.

Massive Scale of the Vulnerability and At-Risk Websites

The vulnerable versions include WordPress 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. According to official WordPress statistics, there are over 400 million websites running these flawed versions, though that number likely includes many that have since updated. A more realistic picture comes from cybersecurity consultant Daniel Card, who analyzed a sample of approximately 3,500 WordPress sites and estimated that less than 15 percent remain vulnerable. When applied to the total population of WordPress sites on the internet, that projection still leaves around 90 million websites potentially exposed to active attacks.

Why the Number of Actual Breaches Remains Limited So Far

Despite the vast attack surface, the number of successfully compromised sites has been contained, thanks to a combination of proactive defenses. The researcher credited WordPress’s forced automatic updates, Cloudflare’s active blocking of exploitation attempts against its hosted sites, and the use of cybersecurity protections like web application firewalls for limiting the immediate damage. Megan Fox, a spokesperson for Automattic, confirmed that all sites hosted on Automattic platforms—including WordPress.com, Pressable, and WPVIP—were protected even before the official patch was released, with code updates deployed immediately across millions of sites upon publication.

What Affected Users Should Do Right Now

If you run a WordPress website, the single most important step is to verify that you are running version 7.0.2 or later. Check your WordPress admin dashboard under “Updates” and apply the patch immediately if you have not already done so. For those who cannot update immediately, deploying a robust web application firewall and implementing strict file permission controls are essential temporary mitigations. Administrators should also review their sites for any unauthorized administrator accounts, suspicious files, or unexpected changes to core WordPress files, which are signs of a successful compromise. After updating, change all administrative passwords and enable two-factor authentication for every user with elevated privileges. For users of managed WordPress hosting, confirm with your provider that the patch has been applied at the server level.

The Bigger Picture: Why Patching Speed Defines Security in 2026

This incident serves as a stark reminder that the window between a patch’s release and active exploitation is shrinking to days, not weeks. The WP2Shell vulnerability was patched and then weaponized almost simultaneously, leaving laggards exposed. Organizations and individual site owners must prioritize a structured patch management process, treating security updates as an emergency rather than a routine maintenance task. Relying on a reputable, multi-layered endpoint protection solution and a web application firewall can buy critical time, but the ultimate defense remains the discipline of applying security patches without delay.

Share This Article