A critical vulnerability in WordPress has led to a wave of hacker attacks
22.07.26
Cybercriminals have launched a massive wave of attacks on websites running on vulnerable versions of WordPress. According to preliminary estimates by cyber security experts, the number of resources under direct threat may amount to tens of millions.
Vulnerability Details and Problem Scope
The developers of the platform recently released a critical update designed to fix two serious vulnerabilities. The company even applied the mechanism of forced renewal of the maximum possible number of resources. Despite the measures taken, research groups from the companies Patchstack, Hexastrike and WatchTowr confirmed that attackers are already actively exploiting these “holes” in security on sites whose owners have not yet had time to install patches.
Prone versions and forecasts
WordPress versions 6.9.0–6.9.4 and 7.0.0–7.0.1 were affected. Statistics indicate that there are about 400 million sites in the world running on these versions, although some of them have been updated after the release of patches. Independent cybersecurity consultant Daniel Card analyzed a sample of 3,500 resources and concluded that nearly 15% of them remain at risk. Based on this data, up to 90 million sites could be potentially compromised.
The danger of the WP2Shell exploit
One of the key threats is a vulnerability called WP2Shell, discovered by Adam Cuse of Searchlight Cyber. In conjunction with another bug discovered, it allows hackers to gain complete remote control over a website.
Protective mechanisms
Experts note that a complete disaster can be prevented thanks to three main factors: automatic updates in WordPress, active filtering of attacks by the Cloudflare service and the use of web firewalls. Representatives of Automattic reported that WordPress.com infrastructure, including Pressable, WPVIP and WP.cloud services, was protected even before the official release of patches due to timely deployment on all of the company’s hosting sites.
If you’re a WordPress admin, the first thing you should do is check the version of your CMS and update to the latest version immediately, if it hasn’t already been done automatically. Despite the efforts of providers, self-monitoring of software relevance remains the best defense for data security.
Don't miss interesting news
Subscribe to our channels and read announcements of high-tech news, tes
Oppo A6 Pro smartphone review: ambitious
Creating new mid-range smartphones is no easy task. Manufacturers have to balance performance, camera capabilities, displays, and the overall cost impact of each component. How the new Oppo A6 Pro balances these factors is discussed in our review.
In-Ear headphones Active Noise Cancellation: how Oppo eliminate noise
In-ear headphones remain one of the most popular form factors due to their lightweight design. However, this design is considered one of the most challenging to implement active noise cancellation (ANC). We’ll explain how Oppo solved this problem.
The Steam Economy: 1% of Games Grab 85% of Revenue
A large-scale study of Steam has exposed the brutal reality of the gaming industry: the vast majority of projects fail to cover even basic costs. We break down how this ‘winner-take-all’ economy works and why success is so elusive for developers.
China Accelerates Government Transition from Windows to Linux
Chinese government agencies are accelerating their move away from Windows in favor of national Linux distributions. The transition, originally slated for February 2027, has been pushed up to late 2026 as part of a push for technological independence.


