Full Breakdown
Hackers Exploit Freshly Patched WordPress Vulnerabilities, Threatening Millions of Sites
7/21/2026, 12:07:06 PM
Exploitation of Newly Patched WordPress Flaws
In the week following WordPress’s emergency release of patches for two critical security flaws, cybersecurity firms observed active exploitation of the still-vulnerable versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. The flaws allow attackers to gain full remote control of a site, a capability dubbed “WP2Shell” after its discovery by Adam Kues of Searchlight Cyber. WordPress responded by enabling forced updates where possible, urging administrators to apply the fixes “immediately.”
Scope and Estimates of At-Risk Sites
WordPress’s own statistics list more than 400 million websites running the affected versions. Cybersecurity consultant Daniel Card sampled roughly 3,500 sites and estimated that fewer than 15 percent remain vulnerable. Applying that rate to the total yields an approximate 90 million sites still exposed, though the exact figure is uncertain because many sites may have been patched after the data were collected.
Official Responses from WordPress and Automattic
WordPress.org issued an urgent advisory recommending immediate updates and activated forced updates for eligible installations. Automattic, the company behind WordPress.com and a major contributor to the open-source project, said its hosted services—including WordPress.com, Pressable, WPVIP, and WP.cloud partners—were already protected before the patches were released and that the updates were deployed “across millions of sites” as soon as they became available. Cloudflare and web-application firewalls were also cited as additional layers blocking attacks on vulnerable sites.
Expert Analysis and Mitigation Efforts
Security firms Patchstack, Hexastrike, and WatchTowr confirmed that exploitation is occurring in the wild, targeting sites that have not yet applied the patches. They recommend that site owners verify their WordPress version, enable automatic updates, and employ web-application firewalls or CDN services such as Cloudflare to mitigate ongoing attempts.
Verbatim Quotes
- “Hackers are breaking into websites that run vulnerable versions of the popular blogging software WordPress, according to several cybersecurity firms.” — TechCrunch article
- “ The vulnerabilities are so severe that WordPress enabled forced updates where possible.” — TechCrunch article
- “all sites hosted by Automattic, including WordPress.com, Pressable, WPVIP, and WP.cloud partners, were protected even before the release. When the code updates were published, we deployed them immediately across millions of sites.” — Megan Fox, spokesperson, Automattic
- “all sites hosted by Automattic, including WordPress.com, Pressable, WPVIP, and WP.cloud partners, were protected even before the release. When the code updates were published, we deployed them immediately across millions of sites.” — Megan Fox, spokesperson, Automattic
- “ One of the critical WordPress bugs was found and reported by Adam Kues of cybersecurity firm Searchlight Cyber, which dubbed it WP2Shell.” — TechCrunch article
