Websites running vulnerable versions of the popular blogging platform WordPress are increasingly being targeted by hackers, according to several cybersecurity firms.
While the exact number of affected sites remains unclear, one estimate suggests that up to 90 million WordPress websites could still be at risk.
Cybersecurity researcher Daniel Card told TechCrunch that after analysing a sample of around 4,200 WordPress websites, he estimates that fewer than 15% remain vulnerable.
Even so, applying that estimate across the broader WordPress ecosystem suggests that as many as 90 million websites could still be exposed.
When combined with a second flaw, the bugs could allow attackers to gain complete remote control of vulnerable WordPress websites.
Websites running vulnerable versions of the popular blogging platform WordPress are increasingly being targeted by hackers, according to several cybersecurity firms. While the exact number of affected sites remains unclear, one estimate suggests that up to 90 million WordPress websites could still be at risk.
The warnings come after WordPress patched two critical security flaws and urged website owners to update their installations immediately. The vulnerabilities were considered so severe that WordPress enabled automatic forced updates for affected versions. Despite the release of the patches, cybersecurity firms including Patchstack, Hexastrike and watchTowr have warned that attackers are already exploiting the flaws on websites that have yet to install the latest updates.
STORY CONTINUES BELOW THIS AD
Determining the exact number of vulnerable websites is difficult because the affected versions—WordPress 6.9.0 through 6.9.4 and WordPress 7.0.0 through 7.0.1—have been gradually receiving security updates. Around 400 million websites are estimated to run these versions, although that figure also includes sites that have already been patched.
Cybersecurity researcher Daniel Card told TechCrunch that after analysing a sample of around 4,200 WordPress websites, he estimates that fewer than 15% remain vulnerable. Even so, applying that estimate across the broader WordPress ecosystem suggests that as many as 90 million websites could still be exposed.
Card attributed the relatively limited number of vulnerable sites to WordPress’ automatic security updates, Cloudflare’s attack mitigation measures and the widespread use of web application firewalls and other cybersecurity protections.
Neither Automattic nor WordPress.org, the organisation responsible for developing WordPress’ open-source software, responded to requests for comment.
One of the critical vulnerabilities, dubbed WP2Shell, was discovered by Adam Kues of cybersecurity firm Searchlight Cyber. When combined with a second flaw, the bugs could allow attackers to gain complete remote control of vulnerable WordPress websites.