Story perspectives
Hackers Exploit WordPress Bugs, 90 Million Sites Still Vulnerable
7/21/2026
1 of 1
Story summary
- Hackers are exploiting two critical WordPress bugs to take control of vulnerable U.S. sites.
- WordPress released patches last week and forced updates for versions 6.9.0-6.9.4 and 7.0.0-7.0.1, which power over 400 million sites.
- Automattic said its hosted sites were protected before the release and updated immediately, while consultant Daniel Card estimates about 90 million sites remain at risk and security firms Patchstack, Hexastrike and WatchTowr reported active exploitation.
