Active Exploitation of Critical WordPress Vulnerabilities Threatens Millions of Sites

Active Exploitation of Critical WordPress Vulnerabilities Threatens Millions of Sites

First seen 20 Jul 2026, 17:39 UTC BeyondmachinesTechcrunchMezhaRss.Slashdotblog.cloudflare.com+1 89% similarity 72.8

Article Content

Browse articles
ThreatCluster

Cybersecurity firms report that hackers are actively exploiting two critical vulnerabilities in WordPress versions 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1. WordPress recently patched these flaws, urging immediate updates. Estimates suggest that around 90 million websites may still be vulnerable. The vulnerabilities allow attackers to gain full remote control of affected sites, posing a significant risk to millions of users. Experts recommend enabling automatic updates and using web firewalls for protection. The vulnerabilities were identified by Adam Kues of Searchlight Cyber, who named one of them WP2Shell. Cloudflare and other security measures are helping to mitigate the attacks. However, many sites remain unpatched, increasing the risk of breaches.

Key Points: • Hackers are exploiting critical vulnerabilities in WordPress affecting millions of sites. • WordPress versions 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1 are at risk; approximately 90 million sites may be vulnerable. • Immediate updates and cybersecurity measures are essential to prevent remote takeovers.

ThreatCluster AI

Timeline

2026-07-13
WordPress patches critical vulnerabilities
WordPress released updates to fix two severe vulnerabilities allowing remote code execution.
Beyondmachines
2026-07-20
Active exploitation reported
Cybersecurity firms confirm hackers are actively exploiting the patched vulnerabilities in WordPress.
Techcrunch
2026-07-20
Experts urge immediate updates
Security experts recommend that site owners update their WordPress versions to prevent attacks.
Mezha

Community

Browse all →