Hackers are actively exploiting vulnerable WordPress installations to compromise websites, according to multiple cybersecurity firms. WordPress released patches for two critical security flaws last week.
Cybersecurity companies have confirmed that attackers are targeting websites running outdated versions of WordPress, the content management system powering roughly 43% of all websites online.
The attacks take advantage of two critical vulnerabilities that WordPress patched in a recent update. The flaws allow attackers to gain unauthorized access and take control of affected websites.
What's at risk
Websites running unpatched WordPress installations remain exposed. The vulnerability affects a significant portion of WordPress users who delay security updates, making them prime targets for automated attack campaigns.
Compromised websites can be used to distribute malware, steal user data, redirect traffic, or serve as launching points for attacks on other systems. Website owners face potential data breaches, loss of service, and reputational damage.
The patch
WordPress released the security patches last week as part of a routine maintenance update. The company has not publicly disclosed specific technical details about the flaws, a standard practice to prevent exploitation while users update their systems.
Security researchers recommend all WordPress administrators apply the latest updates immediately. This includes updating the core WordPress software, plugins, and themes.
Current threat level
The active exploitation indicates attackers have already identified and are weaponizing the flaws. This increases urgency for website owners to patch immediately rather than waiting for scheduled maintenance windows.
Website administrators should verify their current WordPress version and enable automatic security updates where possible. Those managing multiple sites should prioritize patching to prevent widespread compromise.
The incident highlights the ongoing security challenges for WordPress, which remains a frequent target due to its widespread adoption and reliance on third-party plugins that may not receive timely security updates.
Over 36,000 Plex Media servers remain exposed online without security patches, leaving them vulnerable to active exploits. The unpatched systems pose a significant risk to user data and network integrity.
An Ohio man received a 15-year prison sentence for using AI-generated sexually explicit videos to extort and cyberstalk multiple women. The case marks a significant legal action against deepfake-based sexual exploitation.
A security researcher has disclosed a critical zero-day vulnerability in Microsoft Defender dubbed 'ShieldCrash' that grants attackers SYSTEM-level access. The exploit was released publicly following Microsoft's September 2026 Patch Tuesday updates.
A critical window exists to address fundamental security vulnerabilities across systems before widespread exploitation becomes inevitable. Industry experts warn that delayed action could expose infrastructure to coordinated attacks.