Tech news in 3 minutes

WordPress Bugs Exploited by Hackers, Millions at Risk

1 d ago

WordPress critical security flaws are being actively exploited by hackers, with cybersecurity firms warning that tens of millions of websites running vulnerable versions of the popular blogging software remain at risk. Last week, WordPress patched two severe vulnerabilities and forced automatic updates where possible, but attackers are now targeting sites still running susceptible versions 6.9.0 through 6.9.4 and 7.0.0 to 7.0.1. Cybersecurity companies Patchstack, Hexastrike, and WatchTowr have confirmed exploitation in the wild, enabling hackers to take full remote control of vulnerable websites. While WordPress’ official stats show over 400 million websites use flawed versions, cybersecurity consultant Daniel Card estimates that less than 15% of a sample of 4,200 sites are vulnerable, which would still leave roughly 90 million sites at risk. The researcher credited WordPress’ automatic updates, Cloudflare’s attack blocking, and web firewalls for limiting the current number of compromised sites. One critical bug, dubbed WP2Shell by researcher Adam Kues of Searchlight Cyber, allows attackers to combine with another flaw for complete site takeover. Automattic and WordPress.org did not immediately respond to requests for comment. The situation underscores the urgency for website administrators to update WordPress immediately, as the window for exploitation narrows but remains significant for unpatched sites.

View original article

Timeline