Observed Signal · Jul 20, 2026 · Security Vulnerability / Exploit · Source: techcrunch · Impact: 4/5 · Sentiment: Negative

Hackers Exploit Recently Patched WordPress Flaws

Executive Signal Summary

Security researchers and multiple cybersecurity firms warn that attackers are actively exploiting two recently patched critical WordPress vulnerabilities (affecting versions 6.9.0–6.9.4 and 7.0.0–7.0.1). WordPress pushed immediate and, where possible, forced updates after the fixes were released. Firms including Patchstack, Hexastrike, and WatchTowr reported in-the-wild exploitation. Researcher Daniel Card sampled ~4,200 sites and estimates under 15% remain vulnerable, which could extrapolate to roughly 90 million at-risk WordPress sites. The exploit chain includes a vulnerability dubbed WP2Shell, reported by Adam Kues of Searchlight Cyber. Cloudflare and web application firewalls have helped block some attacks while many sites remain exposed.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

WordPress is a major CMS powering a large share of the web; actively exploited critical vulnerabilities threaten publisher sites, site security, ad inventory integrity, and require urgent patching across many properties.

SIGNAL RADAR

Track WordPress Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • WordPress released patches for two critical security flaws and urged immediate updates; forced updates were enabled where possible.
  • Vulnerable WordPress versions are 6.9.0 through 6.9.4, and 7.0.0 to 7.0.1.
  • Cybersecurity firms Patchstack, Hexastrike, and WatchTowr warned that hackers are exploiting these vulnerabilities in the wild.
  • Researcher Daniel Card sampled ~4,200 WordPress sites and estimated under 15% remain vulnerable, which extrapolates to about 90 million potentially at-risk sites.
  • One critical bug, dubbed WP2Shell, was found and reported by Adam Kues of Searchlight Cyber and can be combined with the other flaw to allow full remote takeover of vulnerable websites.

Connected Companies & Entities

4 Entities mapped

“Automattic, as well as WordPress.org, the project that develops WordPress’ open-source code, did not immediately respond to a request for co...”

“The researcher credited WordPress with pushing automatic updates, Cloudflare with blocking attacks against vulnerable websites, and websites...”

“Automattic, as well as WordPress.org, the project that develops WordPress’ open-source code, did not immediately respond to a request for co...”

“Lorenzo Franceschi-Bicchierai is a Senior Writer at TechCrunch, where he covers hacking, cybersecurity, surveillance, and privacy....”

Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: techcrunch•Published: Jul 20, 2026
Original Coverage Title: “Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

SecurityJun 22, 2026

AI Finds 300+ WordPress Plugin Zero‑Days in 72 Hours

A developer describes how AI-powered security tooling and bad practices have rapidly increased critical vulnerabilities across the WordPress plugin ecosystem. Security researchers — in a pipeline reported by Help Net Security and summarized in Patchstack's 2026 report — combined AI static analysis with automated verification to surface more than 300 critical zero-days in about 72 hours, with manual verification before disclosure. Patchstack attributes part of the problem to “vibe coding,” where developers ship LLM-generated plugin code they cannot fully audit. The author recounts finding 35 bugs (three critical) in their own AI chatbot plugin and urges treating model output as untrusted, applying standard WordPress security functions (escaping, capability checks, nonces, prepared DB statements), and establishing a vulnerability disclosure channel. Patchstack metrics show a weighted-median five-hour window from public disclosure to mass exploitation and indicate many plugins lack timely patches. The post notes an EU requirement (by Sept 2026) for a vulnerability disclosure program for plugins/themes distributed to EU users.

Read assessment
CMS security / supply‑chain attackApr 14, 2026

Backdoors Found in Dozens of WordPress Plugins

Security researchers discovered a backdoor inserted into dozens of WordPress plug-ins after the plug-in maker Essential Plugin was acquired by a new corporate owner. Anchor Hosting founder Austin Ginder alerted the community after finding the supply‑chain compromise; the malicious code reportedly sat dormant for months and activated earlier in April 2026 to distribute additional malicious payloads to sites running the affected plug-ins. Essential Plugin states it has over 400,000 installs and more than 15,000 customers, while WordPress shows the affected plug-ins in over 20,000 active installations. The plug-ins have been removed from the WordPress directory and marked permanently closed. Site owners are advised to check for and remove any affected plug-ins.

Read assessment
Content Management System (CMS) SecurityApr 15, 2026

WordPress Plugins Infected with Backdoor

A security researcher, Austin Ginder, discovered that more than 30 WordPress plugins were modified to include a backdoor allowing attackers to inject malicious content into websites. The affected plugins — originally developed by an Indian team called WP Online Support and later sold in early 2025 to an anonymous buyer using the nickname “Kris,” who renamed the collection Essential Plugin — remained dormant until the backdoor was activated in early April 2026. Injected payloads reportedly loaded spam links, redirects, fake pages and crypto-related links from a remote server, and the injections were cloaked so only Google’s crawler could see them. Essential Plugin says the infected addons had over 400,000 installs; the extensions have since been disabled in the WordPress store. Ginder published a patch and a removal recommendation for site operators.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.