Hackers Exploiting Critical WordPress Flaws, Up to 90 Million Sites Potentially at Risk

Hackers are actively breaking into websites running vulnerable versions of WordPress after two critical security flaws were disclosed, with an estimated 90 million sites potentially exposed, according to cybersecurity researchers.

WordPress patched the two vulnerabilities last week, urging website operators to update “immediately” and enabling forced automatic updates where possible. Despite that response, cybersecurity firms Patchstack, Hexastrike, and WatchTowr have all confirmed that hackers are exploiting the flaws in the wild as of Monday, July 21, 2026, taking control of sites still running susceptible versions.

The affected versions are WordPress 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. WordPress’ official statistics show more than 400 million websites run those versions, though that figure likely does not account for sites recently patched. Cybersecurity consultant Daniel Card, who analyzed a sample of approximately 4,200 WordPress websites, estimates fewer than 15% remain vulnerable. Applied across the broader WordPress install base, that projection suggests roughly 90 million sites could still be at risk.

One of the critical bugs was discovered and reported by Adam Kues of cybersecurity firm Searchlight Cyber, which named it WP2Shell. When combined with the second flaw, the vulnerabilities allow hackers to take full remote control of a targeted website.

Card credited WordPress’ automatic update push, Cloudflare’s blocking of attacks against vulnerable sites, and the use of web application firewalls with limiting the number of sites that could currently be compromised.

Automattic, the company behind WordPress, and WordPress.org, the open-source project that develops the software’s code, did not respond to requests for comment at the time of reporting.

Source: TechCrunch

This article was generated by AI and cites original sources.
Scroll to Top