Breaking
TRAdapazarı'nda otomobil ile kamyon çarpıştı: Yakıt sızıntısı sakızla önlendiTRMuratpaşa'da Yangın Çıkan Dairede Pencereden Sarkan 2 Kişi KurtarıldıTRABD Başkan Yardımcısı Vance'e Yakın İsimlerden Trump-Netanyahu Görüşmesini Engelleme GirişimiTROğuzhan Uğur'un Ahbap Derneği soruşturmasındaki savcılık ve hakimlik ifadeleri ortaya çıktıTRABD Dışişleri Bakanlığı'ndan Orta Doğu Gerilimi UyarısıTRGöztepe'de Juan Silva ve Anthony Dennis'in transfer durumuTRKremlin: NATO askerlerinin Ukrayna'ya konuşlandırılması kabul edilemezTRApple, iOS 27 Beta 4 Güncellemesini YayınladıTRPetrol Fiyatları Diplomatik Çözüm Beklentisiyle Düştü, Goldman Sachs'tan 120 Dolar SenaryosuTRFransa'dan 15 Yaş Altına Sosyal Medya Yasağı OnayıTRAdapazarı'nda otomobil ile kamyon çarpıştı: Yakıt sızıntısı sakızla önlendiTRMuratpaşa'da Yangın Çıkan Dairede Pencereden Sarkan 2 Kişi KurtarıldıTRABD Başkan Yardımcısı Vance'e Yakın İsimlerden Trump-Netanyahu Görüşmesini Engelleme GirişimiTROğuzhan Uğur'un Ahbap Derneği soruşturmasındaki savcılık ve hakimlik ifadeleri ortaya çıktıTRABD Dışişleri Bakanlığı'ndan Orta Doğu Gerilimi UyarısıTRGöztepe'de Juan Silva ve Anthony Dennis'in transfer durumuTRKremlin: NATO askerlerinin Ukrayna'ya konuşlandırılması kabul edilemezTRApple, iOS 27 Beta 4 Güncellemesini YayınladıTRPetrol Fiyatları Diplomatik Çözüm Beklentisiyle Düştü, Goldman Sachs'tan 120 Dolar SenaryosuTRFransa'dan 15 Yaş Altına Sosyal Medya Yasağı Onayı
Newsgather
BackHackers Actively Exploiting Critical WordPress Vulnerabilities
Hackers Actively Exploiting Critical WordPress Vulnerabilities
Urgent
TechCrunch14 hours agoTech2 min readUnited States

Hackers Actively Exploiting Critical WordPress Vulnerabilities

Quick Look

  • Cybersecurity firms report hackers are actively exploiting critical vulnerabilities in popular WordPress software, affecting potentially tens of millions of websites despite recent patches and forced updates.
  • Users are urged to update immediately to mitigate risks.

AI-generated summary

Why It Matters

WordPress recently patched two critical security flaws (versions 6.9.0-6.9.4 and 7.0.0-7.0.1) and urged immediate updates, even enabling forced updates where possible.

Font size

Hackers are breaking into websites that run vulnerable versions of the popular blogging software WordPress, according to several cybersecurity firms. One estimate puts the number of vulnerable WordPress websites at tens of millions as of Monday.

Last week, WordPress patched two critical security flaws, urging people who run its software on their websites to update it “immediately.” The vulnerabilities are so severe that WordPress enabled forced updates where possible. Since then, cybersecurity companies Patchstack, Hexastrike, and WatchTowr have all warned that hackers are exploiting the vulnerabilities in the wild, meaning they are taking over websites that are still running susceptible versions of WordPress.

It’s unclear how many WordPress-powered websites on the internet are at risk, but it’s possible to make some educated guesses. The vulnerable versions of WordPress are 6.9.0 through 6.9.4, and 7.0.0 to 7.0.1. According to WordPress’ official stats, there are more than 400 million websites that run those flawed versions, although these statistics likely don’t reflect websites that have recently been patched.

Cybersecurity consultant Daniel Card, who told TechCrunch that he looked at a sample of around 3,500 WordPress websites, estimates that less than 15% are vulnerable. Applying Card’s projection across the total population of WordPress websites on the internet, the total figure would still be around 90 million.

The researcher credited WordPress with pushing automatic updates, Cloudflare with blocking attacks against vulnerable websites, and websites using cybersecurity protections such as web firewalls for the limited number of sites that could currently be hacked.

WordPress.org, the project that develops WordPress’ open source code, did not immediately respond to a request for comment. Megan Fox, a spokesperson for Automattic, the company that runs WordPress.com and contributes to the open source project, told TechCrunch that “all sites hosted by Automattic, including WordPress.com, Pressable, WPVIP, and WP.cloud partners, were protected even before the release. When the code updates were published, we deployed them immediately across millions of sites.”

What to Watch

AI outlook — possibilities, not facts

  • WordPress users will continue to be urged to update their software immediately.

    Very likely · Within weeks

  • Hackers will continue to exploit unpatched WordPress sites.

    Likely · Within weeks

Open Questions

  • What is the exact number of currently vulnerable WordPress websites?
  • What is the full extent of the exploitation by hackers?

Related Topics

This article was originally published by TechCrunch.

Related Stories

More on this topicwordpress