Hackers Are Exploiting Recently Patched WordPress Bugs, Putting Millions of Websites at Risk


Source: Lorenzo Franceschi-Bicchierai / techcrunch.com

Millions of Websites at Risk as Hackers Exploit WordPress Bugs

WordPress, the popular blogging software, has recently patched two critical security flaws that were urging users to update their software ‘immediately.’ However, despite the urgent patch, hackers are still exploiting the vulnerabilities, putting millions of websites at risk.

According to several cybersecurity firms, including Patchstack, Hexastrike, and WatchTowr, hackers are breaking into websites that run vulnerable versions of WordPress. The vulnerabilities are so severe that WordPress enabled forced updates where possible, but it seems that not all websites have been updated in time.

How Many Websites Are at Risk?

The vulnerable versions of WordPress are 6.9.0 through 6.9.4, and 7.0.0 to 7.0.1. According to WordPress’ official stats, there are more than 400 million websites that run those flawed versions. However, these statistics likely don’t reflect websites that have recently been patched.

Cybersecurity consultant Daniel Card estimates that less than 15% of WordPress websites are vulnerable, which would put the total number of at-risk websites at around 90 million. However, this number could be even higher, as it’s unclear how many websites have not been updated in time.

The researcher credits WordPress with pushing automatic updates, Cloudflare with blocking attacks against vulnerable websites, and websites using cybersecurity protections such as web firewalls for the limited number of sites that could currently be hacked.

One of the critical WordPress bugs was found and reported by Adam Kues of cybersecurity firm Searchlight Cyber, which dubbed it WP2Shell. Paired with the other bug, hackers can take full remote control of vulnerable websites.

Cybersecurity Experts Weigh In

Cybersecurity experts are urging website owners to update their WordPress software as soon as possible to avoid falling victim to these vulnerabilities. ‘It’s crucial that website owners update their WordPress software immediately to prevent their sites from being hacked,’ says Daniel Card.

While some website owners may be unaware of the vulnerabilities or may be hesitant to update their software, the risks are very real. Hackers can take full remote control of vulnerable websites, which can lead to a range of issues, including data breaches, financial losses, and reputational damage.

As the situation continues to unfold, cybersecurity experts are warning website owners to be vigilant and take immediate action to protect their sites.

Automattic, the company behind WordPress, has not commented on the situation, but it’s clear that the issue is serious and requires urgent attention.

In the meantime, website owners are advised to keep their WordPress software up to date, use cybersecurity protections such as web firewalls, and monitor their sites closely for any signs of suspicious activity.

By taking these precautions, website owners can help protect their sites from the latest WordPress vulnerabilities and prevent potential data breaches and financial losses.

What Can You Do to Protect Your Website?

  • Update your WordPress software to the latest version.
  • Use cybersecurity protections such as web firewalls.
  • Monitor your site closely for any signs of suspicious activity.
  • Keep your software up to date and secure.

By following these steps, website owners can help protect their sites from the latest WordPress vulnerabilities and prevent potential data breaches and financial losses.