Cybercriminals are actively hijacking millions of WordPress websites globally by exploiting two recently patched critical security flaws to gain full remote control over vulnerable systems. Multiple cybersecurity firms have confirmed active exploitation in the wild, with estimates suggesting that tens of millions of websites remained exposed as of Monday.
Active Exploitation of Patched Vulnerabilities
Last week, WordPress patched two critical security flaws, urging administrators to update their installations immediately. The severity of these vulnerabilities prompted WordPress to trigger forced automatic updates where possible. Despite these efforts, cybersecurity firms Patchstack, Hexastrike, and WatchTowr have all warned that malicious actors are actively exploiting the security loopholes to seize control of unpatched websites.
Estimating the Scale of the Threat
Determining the exact number of compromised or at-risk WordPress sites remains challenging, though data allows for calculated projections. The security flaws affect WordPress versions 6.9.0 through 6.9.4, as well as 7.0.0 to 7.0.1. Official statistics indicate that over 400 million websites run these specific versions, though this figure does not fully account for recent security patches.
To gauge the real-world exposure, cybersecurity consultant Daniel Card analysed a sample of approximately 3,500 WordPress sites. He estimated that less than 15% of those sites remain vulnerable. However, when applying Card’s 15% projection to the total population of WordPress websites across the internet, the number of exposed sites still reaches a staggering 90 million.
Mitigation Efforts and Platform Defences
Security researchers credit several proactive measures for limiting the damage. Alongside WordPress’s automatic update push, Cloudflare has been actively blocking attacks targeting the flaws, while web application firewalls (WAFs) have shielded many potentially vulnerable systems.
While WordPress.org has not yet commented on the situation, Automattic—the company behind WordPress.com—confirmed its infrastructure is secure. Megan Fox, a spokesperson for Automattic, stated that all sites hosted on their platform, including WordPress.com, Pressable, WPVIP, and WP.cloud partners, were protected prior to the public disclosure. Fox added that the code updates were deployed across millions of hosted sites immediately upon release.
The Anatomy of the WP2Shell Exploit
One of the critical bugs involved in these attacks was found and reported by Adam Kues, a researcher at cybersecurity firm Searchlight Cyber. Dubbed “WP2Shell”, this vulnerability can be chained with the second flaw, allowing remote attackers to gain complete administrative control over targeted WordPress websites.
