{"id":64115,"date":"2026-07-20T15:24:50","date_gmt":"2026-07-20T19:24:50","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=64115"},"modified":"2026-07-20T15:24:50","modified_gmt":"2026-07-20T19:24:50","slug":"wordpress-bugs-exploit-risk","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/wordpress-bugs-exploit-risk\/","title":{"rendered":"Hackers Exploit Patched WordPress Bugs, Millions of Sites at Risk"},"content":{"rendered":"<p>Hackers are actively exploiting two critical <a href=\"https:\/\/overcentral.com\/en\/may-patch-tuesday-record-vulnerabilities\/\" title=\"May Patch Tuesday Fixes Record 1,018 Security Vulnerabilities\" data-iacss-internal=\"1\">security vulnerabilities<\/a> in WordPress that were patched last week, putting tens of millions of websites at risk of complete takeover. Cybersecurity firms <a href=\"https:\/\/patchstack.com\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Patchstack<\/a>, Hexastrike, and WatchTowr have all confirmed that the flaws are being exploited in the wild, as administrators of vulnerable sites have failed to apply the urgent updates. The situation underscores the persistent danger of unpatched software, even when a fix is readily available and automatically pushed to millions of hosts.<\/p>\n<h2>WordPress Bugs Allow Full Remote Code Execution<\/h2>\n<p>The two vulnerabilities, which were patched in the <a href=\"https:\/\/wordpress.org\/news\/2026\/03\/wordpress-7-0-2\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">WordPress 7.0.2 release<\/a>, allow attackers to achieve complete remote control of a vulnerable website. One of the flaws, discovered and reported by Adam Kues of Searchlight Cyber and dubbed <a href=\"https:\/\/overcentral.com\/en\/wp2shell-wordpress-vulnerability\/\" title=\"wp2shell WordPress Flaw Unlocks Unauthenticated Code Execution\" data-iacss-internal=\"1\">WP2Shell<\/a>, enables an attacker to execute arbitrary code on the server. When combined with the second bug, an attacker can bypass all authentication and take full administrative control, effectively owning the site and its data. WordPress rated the flaws as critical and urged all users to update \u201cimmediately,\u201d implementing forced automatic updates where possible to staunch the bleeding.<\/p>\n<h2>Massive Scale of the Vulnerability and At-Risk Websites<\/h2>\n<p>The vulnerable versions include WordPress 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. According to official WordPress statistics, there are over 400 million websites running these flawed versions, though that number likely includes many that have since updated. A more realistic picture comes from cybersecurity consultant Daniel Card, who analyzed a sample of approximately 3,500 WordPress sites and estimated that less than 15 percent remain vulnerable. When applied to the total population of WordPress sites on the internet, that projection still leaves around 90 million websites potentially exposed to active attacks.<\/p>\n<h3>Why the Number of Actual Breaches Remains Limited So Far<\/h3>\n<p>Despite the vast attack surface, the number of successfully compromised sites has been contained, thanks to a combination of proactive defenses. The researcher credited WordPress\u2019s forced automatic updates, <a href=\"https:\/\/overcentral.com\/en\/cloudflare-ai-bot-controls\/\" title=\"Cloudflare adds granular AI bot controls for search, training, agent crawlers\" data-iacss-internal=\"1\">Cloudflare<\/a>\u2019s active blocking of exploitation attempts against its hosted sites, and the use of cybersecurity protections like web application firewalls for limiting the immediate damage. Megan Fox, a spokesperson for <a href=\"https:\/\/wordpress.com\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Automattic<\/a>, confirmed that all sites hosted on Automattic platforms\u2014including WordPress.com, Pressable, and WPVIP\u2014were protected even before the official patch was released, with code updates deployed immediately across millions of sites upon publication.<\/p>\n<h2>What Affected Users Should Do Right Now<\/h2>\n<p>If you run a WordPress website, the single most important step is to verify that you are running version 7.0.2 or later. Check your WordPress admin dashboard under \u201cUpdates\u201d and apply the patch immediately if you have not already done so. For those who cannot update immediately, deploying a robust web application firewall and implementing strict file permission controls are essential temporary mitigations. Administrators should also review their sites for any unauthorized administrator accounts, suspicious files, or unexpected changes to core WordPress files, which are signs of a successful compromise. After updating, change all administrative passwords and enable two-factor authentication for every user with elevated privileges. For users of managed WordPress hosting, confirm with your provider that the patch has been applied at the server level.<\/p>\n<h2>The Bigger Picture: Why Patching Speed Defines Security in 2026<\/h2>\n<p>This incident serves as a stark reminder that the window between a patch\u2019s release and active exploitation is shrinking to days, not weeks. The WP2Shell vulnerability was patched and then weaponized almost simultaneously, leaving laggards exposed. Organizations and individual site owners must prioritize a structured patch management process, treating security updates as an emergency rather than a routine maintenance task. Relying on a reputable, multi-layered endpoint protection solution and a web application firewall can buy critical time, but the ultimate defense remains the discipline of applying security patches without delay.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hackers are actively exploiting two critical security vulnerabilities in WordPress that were patched last week, putting tens of millions of websites at risk of complete takeover. Cybersecurity firms Patchstack, Hexastrike, and WatchTowr have all confirmed that the flaws are being exploited in the wild, as administrators of vulnerable sites have failed to apply the urgent [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":90487,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/64115.png","fifu_image_alt":"Hackers Exploit Patched WordPress Bugs, Millions of Sites at Risk","footnotes":""},"categories":[349],"tags":[],"class_list":["post-64115","post","type-post","status-publish","format-standard","has-post-thumbnail","category-articles"],"fifu_image_url":"https:\/\/cards.overcentral.com\/cards\/en\/64115.png","fifu_image_alt":"Hackers Exploit Patched WordPress Bugs, Millions of Sites at Risk","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/64115","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=64115"}],"version-history":[{"count":0,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/64115\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/90487"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=64115"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=64115"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=64115"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}