Two critical security flaws in WordPress are being actively exploited by hackers to remotely take over websites. A cybersecurity researcher estimates tens of millions of sites could be affected.
The Vulnerability
Two critical bugs in WordPress software have created a window for attackers to gain remote code execution on vulnerable websites. The flaws were recently patched, but hackers are already exploiting unpatched installations.
Scale of Impact
The potential reach is substantial. WordPress powers approximately 43% of all websites globally, making it a prime target. Cybersecurity researchers estimate that tens of millions of websites could be compromised if administrators fail to apply the patches promptly.
Active Exploitation
Attackers are not waiting. Reports indicate active exploitation campaigns targeting websites still running vulnerable versions of WordPress. Once compromised, hackers gain the ability to execute arbitrary code, install malware, steal data, or redirect traffic.
Affected Sites
Small businesses, blogs, e-commerce platforms, and enterprise websites are all potentially at risk. Any WordPress installation that hasn't been updated to the patched version remains vulnerable.
Recommended Actions
WordPress administrators should immediately:
- Update WordPress to the latest patched version
- Update all plugins and themes
- Enable automatic updates if possible
- Review site access logs for suspicious activity
- Consider using security plugins for added protection
Timeline Matters
The window between patch release and widespread exploitation is often narrow. Website owners who delay updates significantly increase their risk of compromise.
This incident underscores the critical importance of timely security patching across web infrastructure. With WordPress powering such a large portion of the internet, vulnerabilities in the platform have immediate, widespread implications.
The FCC is preparing to use its newly granted power to retroactively ban previously approved DJI gadgets imported into the United States. The action targets suspected front companies created to circumvent the foreign drone ban on the Chinese manufacturer.
Flock Safety, a major license plate recognition camera company, has repeatedly provided misleading information to city councils, police departments, and the public, according to an ACLU investigation. The findings raise questions about the accuracy of claims made by the surveillance technology provider.
Prophet Security released a practical framework for assessing AI SOC platforms, helping organizations evaluate solutions based on real-world performance rather than controlled demonstrations.
Hackers are actively exploiting vulnerable WordPress installations to compromise websites, according to multiple cybersecurity firms. WordPress released patches for two critical security flaws last week.