Techcrunch
Active Exploitation of Critical WordPress Vulnerabilities Threatens Millions of Sites
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Cybersecurity firms report that hackers are actively exploiting two critical vulnerabilities in WordPress versions 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1. WordPress recently patched these flaws, urging immediate updates. Estimates suggest that around 90 million websites may still be vulnerable. The vulnerabilities allow attackers to gain full remote control of affected sites, posing a significant risk to millions of users. Experts recommend enabling automatic updates and using web firewalls for protection. The vulnerabilities were identified by Adam Kues of Searchlight Cyber, who named one of them WP2Shell. Cloudflare and other security measures are helping to mitigate the attacks. However, many sites remain unpatched, increasing the risk of breaches.
Key Points: • Hackers are exploiting critical vulnerabilities in WordPress affecting millions of sites. • WordPress versions 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1 are at risk; approximately 90 million sites may be vulnerable. • Immediate updates and cybersecurity measures are essential to prevent remote takeovers.