Hackers are breaking into web sites that run susceptible variations of the favored running a blog software program WordPress, in keeping with a number of cybersecurity companies. One estimate places the variety of susceptible WordPress web sites at tens of tens of millions as of Monday.
Final week, WordPress patched two critical security flaws, urging individuals who run its software program on their web sites to replace it “instantly.” The vulnerabilities are so extreme that WordPress enabled pressured updates the place doable. Since then, cybersecurity firms Patchstack, Hexastrike, and WatchTowr have all warned that hackers are exploiting the vulnerabilities within the wild, which means they’re taking on web sites which can be nonetheless working vulnerable variations of WordPress.
It’s unclear what number of WordPress-powered web sites on the web are in danger, however it’s doable to make some educated guesses. The susceptible variations of WordPress are 6.9.0 via 6.9.4, and seven.0.0 to 7.0.1. Based on WordPress’ official stats, there are greater than 400 million web sites that run these flawed variations, though these statistics doubtless don’t replicate web sites which have lately been patched.
Cybersecurity advisor Daniel Card, who advised TechCrunch that he checked out a pattern of round 4,200 WordPress web sites, estimates that less than 15% are susceptible. Making use of Card’s projection throughout the total population of WordPress web sites on the web, the whole determine would nonetheless be round 90 million.
The researcher credited WordPress with pushing automated updates, Cloudflare with blocking attacks in opposition to susceptible web sites, and web sites utilizing cybersecurity protections reminiscent of net firewalls for the restricted variety of websites that would presently be hacked.
Automattic, in addition to WordPress.org, the venture that develops WordPress’ open-source code, didn’t instantly reply to a request for remark.
One of many important WordPress bugs was found and reported by Adam Kues of cybersecurity agency Searchlight Cyber, which dubbed it WP2Shell. Paired with the opposite bug, hackers can take full distant management of susceptible web sites.
Whenever you buy via hyperlinks in our articles, we may earn a small commission. This doesn’t have an effect on our editorial independence.

