Hackers Exploit Recently Patched WordPress Flaws
Security researchers and multiple cybersecurity firms warn that attackers are actively exploiting two recently patched critical WordPress vulnerabilities (affecting versions 6.9.0–6.9.4 and 7.0.0–7.0.1). WordPress pushed immediate and, where possible, forced updates after the fixes were released. Firms including Patchstack, Hexastrike, and WatchTowr reported in-the-wild exploitation. Researcher Daniel Card sampled ~4,200 sites and estimates under 15% remain vulnerable, which could extrapolate to roughly 90 million at-risk WordPress sites. The exploit chain includes a vulnerability dubbed WP2Shell, reported by Adam Kues of Searchlight Cyber. Cloudflare and web application firewalls have helped block some attacks while many sites remain exposed.
- •WordPress released patches for two critical security flaws and urged immediate updates; forced updates were enabled where possible.
- •Vulnerable WordPress versions are 6.9.0 through 6.9.4, and 7.0.0 to 7.0.1.
- •Cybersecurity firms Patchstack, Hexastrike, and WatchTowr warned that hackers are exploiting these vulnerabilities in the wild.
