A critical vulnerability in WordPress has led to a wave of hacker attacks
22.07.26
Cybercriminals have launched a massive wave of attacks on websites running on vulnerable versions of WordPress. According to preliminary estimates by cyber security experts, the number of resources under direct threat may amount to tens of millions.
Vulnerability Details and Problem Scope
The developers of the platform recently released a critical update designed to fix two serious vulnerabilities. The company even applied the mechanism of forced renewal of the maximum possible number of resources. Despite the measures taken, research groups from the companies Patchstack, Hexastrike and WatchTowr confirmed that attackers are already actively exploiting these “holes” in security on sites whose owners have not yet had time to install patches.
Prone versions and forecasts
WordPress versions 6.9.0–6.9.4 and 7.0.0–7.0.1 were affected. Statistics indicate that there are about 400 million sites in the world running on these versions, although some of them have been updated after the release of patches. Independent cybersecurity consultant Daniel Card analyzed a sample of 3,500 resources and concluded that nearly 15% of them remain at risk. Based on this data, up to 90 million sites could be potentially compromised.
The danger of the WP2Shell exploit
One of the key threats is a vulnerability called WP2Shell, discovered by Adam Cuse of Searchlight Cyber. In conjunction with another bug discovered, it allows hackers to gain complete remote control over a website.
Protective mechanisms
Experts note that a complete disaster can be prevented thanks to three main factors: automatic updates in WordPress, active filtering of attacks by the Cloudflare service and the use of web firewalls. Representatives of Automattic reported that WordPress.com infrastructure, including Pressable, WPVIP and WP.cloud services, was protected even before the official release of patches due to timely deployment on all of the company’s hosting sites.
If you’re a WordPress admin, the first thing you should do is check the version of your CMS and update to the latest version immediately, if it hasn’t already been done automatically. Despite the efforts of providers, self-monitoring of software relevance remains the best defense for data security.
Don't miss interesting news
Subscribe to our channels and read announcements of high-tech news, tes
Oppo A6 Pro smartphone review: ambitious
Creating new mid-range smartphones is no easy task. Manufacturers have to balance performance, camera capabilities, displays, and the overall cost impact of each component. How the new Oppo A6 Pro balances these factors is discussed in our review.
Logitech Signature Comfort Plus Combo MK880 review: comfort in priority
Logitech Signature Comfort Plus Combo MK880 is a wireless keyboard and mouse set that focuses on comfort during long hours of work, not only due to the ergonomics of the case, but also constructive additions.
A critical vulnerability in WordPress has led to a wave of hacker attacks
Hackers are attacking millions of WordPress sites by exploiting recently patched vulnerabilities in versions 6.9.0-7.0.1.
Hugging Face’s infrastructure was attacked by an autonomous system of AI agents
An autonomous system of AI agents successfully hacked Hugging Face’s production infrastructure.


