WordPress critical bugs exploited in the wild, millions of sites at risk
Original: Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk
Why This Matters
Active exploitation of critical WordPress flaws puts tens of millions of websites globally at immediate risk.
Hackers are actively exploiting two critical vulnerabilities in WordPress versions 6.9.0–6.9.4 and 7.0.0–7.0.1, patched last week. Cybersecurity firms Patchstack, Hexastrike, and WatchTowr confirmed in-the-wild attacks. An estimated 90 million websites may still be vulnerable as of July 20, 2026.
WordPress patched two critical security flaws last week and urged site operators to update "immediately," enabling forced automatic updates where possible. Despite this, cybersecurity firms Patchstack, Hexastrike, and WatchTowr have all confirmed that hackers are actively exploiting the vulnerabilities to take over unpatched websites.
The affected versions are WordPress 6.9.0 through 6.9.4, and 7.0.0 through 7.0.1. WordPress' official stats show over 400 million websites run these versions, though the figure does not account for recently patched sites. Cybersecurity consultant Daniel Card sampled approximately 4,200 WordPress sites and estimated fewer than 15% remain vulnerable — which, applied broadly, still amounts to roughly 90 million at-risk websites.
One of the critical bugs, dubbed "WP2Shell," was discovered and reported by Adam Kues of Searchlight Cyber. When combined with the second vulnerability, attackers can gain full remote control of affected websites. Card credited WordPress' auto-update push, Cloudflare's attack blocking, and web application firewalls for limiting the overall impact. Automattic and WordPress.org had not responded to requests for comment at time of publication.