Hackers are breaking into websites running vulnerable versions of the popular blogging software WordPress, according to several cybersecurity firms. One estimate puts the number of vulnerable WordPress sites in the tens of millions as of Monday.
last week, WordPress fixes two critical security flawsurging people running its software on their sites to update it “immediately.” The vulnerabilities are so serious that WordPress allowed forced updates where possible. Since then, cybersecurity companies Patchstack, Hexastrike and WatchTowr everyone has been warned that hackers exploit vulnerabilities in the wild, meaning they take over websites that are still running vulnerable versions of WordPress.
It’s unclear how many WordPress-powered sites on the Internet are at risk, but it’s possible to make some educated guesses. Vulnerable versions of WordPress are 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1. According to official WordPress statistics, there are more than 400 million sites running these flawed versions, although these statistics likely do not reflect sites that have recently been patched.
Cybersecurity consultant Daniel Card, who told TechCrunch he reviewed a sample of about 3,500 WordPress websites, estimates that less than 15% they are vulnerable. Application of the projection of the card along it total population of WordPress sites on the internet, the total number would still be around 90 million.
The researcher credited WordPress with promoting automatic updates, Cloudflare with blocking attacks against vulnerable websites and websites that use cyber security protections such as web firewalls for the limited number of websites that could currently be breached.
WordPress.org, the project that develops the open source code of WordPress, did not immediately respond to a request for comment. Megan Fox, a spokeswoman for Automattic, the company that runs WordPress.com and contributes to the open source project, told TechCrunch that “all websites hosted by Automattic, including WordPress.comPartners , Pressable, WPVIP and WP.cloud were protected even before launch. When the patches were released, we immediately deployed them to millions of sites.”
One of the critical WordPress errors found and reported with Adam Kues of cybersecurity firm Searchlight Cyber, which named it WP2Shell. Combined with the other flaw, hackers can take complete remote control of vulnerable websites.
When you purchase through links in our articles, we may earn a small commission. This does not affect our editorial independence.
