Hackers are actively exploiting vulnerable WordPress installations to compromise websites, according to multiple cybersecurity firms. WordPress released patches for two critical security flaws last week.
Cybersecurity companies have confirmed that attackers are targeting websites running outdated versions of WordPress, the content management system powering roughly 43% of all websites online.
The attacks take advantage of two critical vulnerabilities that WordPress patched in a recent update. The flaws allow attackers to gain unauthorized access and take control of affected websites.
What's at risk
Websites running unpatched WordPress installations remain exposed. The vulnerability affects a significant portion of WordPress users who delay security updates, making them prime targets for automated attack campaigns.
Compromised websites can be used to distribute malware, steal user data, redirect traffic, or serve as launching points for attacks on other systems. Website owners face potential data breaches, loss of service, and reputational damage.
The patch
WordPress released the security patches last week as part of a routine maintenance update. The company has not publicly disclosed specific technical details about the flaws, a standard practice to prevent exploitation while users update their systems.
Security researchers recommend all WordPress administrators apply the latest updates immediately. This includes updating the core WordPress software, plugins, and themes.
Current threat level
The active exploitation indicates attackers have already identified and are weaponizing the flaws. This increases urgency for website owners to patch immediately rather than waiting for scheduled maintenance windows.
Website administrators should verify their current WordPress version and enable automatic security updates where possible. Those managing multiple sites should prioritize patching to prevent widespread compromise.
The incident highlights the ongoing security challenges for WordPress, which remains a frequent target due to its widespread adoption and reliance on third-party plugins that may not receive timely security updates.
Meta's Ray-Ban smartglasses can record video without obvious indicators, raising child safety concerns. The company places responsibility on users to avoid 'actively exploiting' the technology rather than implementing technical safeguards.
Researchers have identified a critical security flaw in aftermarket alarm systems installed by dealerships across millions of US vehicles. The devices can be hacked to unlock cars, enable tracking, and disable engine functionality.
The FCC is preparing to use its newly granted power to retroactively ban previously approved DJI gadgets imported into the United States. The action targets suspected front companies created to circumvent the foreign drone ban on the Chinese manufacturer.
Flock Safety, a major license plate recognition camera company, has repeatedly provided misleading information to city councils, police departments, and the public, according to an ACLU investigation. The findings raise questions about the accuracy of claims made by the surveillance technology provider.