All posts

WordPress bugs under active attack, 90M sites still at risk

Huma ShaziaJuly 22, 2026 at 7:16 AM4 min read
WordPress bugs under active attack, 90M sites still at risk

Key Takeaways

WordPress bugs under active attack, 90M sites still at risk
Source: TechCrunch
  • Two critical WordPress vulnerabilities (versions 6.9.0-6.9.4 and 7.0.0-7.0.1) are under active exploitation despite patches released last week
  • Security consultant Daniel Card estimates 15% of WordPress sites remain unpatched, translating to roughly 90 million vulnerable websites
  • Attackers can achieve full remote control of vulnerable sites by chaining the two bugs together

Hackers are actively breaking into WordPress websites running unpatched software, multiple cybersecurity firms confirmed Monday. Despite WordPress pushing emergency automatic updates last week, an estimated 90 million sites remain vulnerable to two critical bugs that allow complete remote takeover.

ℹ️

Disclosure

Some links in this post are affiliate links — Logicity earns a commission if you sign up, at no extra cost to you. We only link products we have used or actively recommend.

Patchstack, Hexastrike, and WatchTowr have all observed exploitation in the wild since WordPress released patches for versions 6.9.0 through 6.9.4 and 7.0.0 to 7.0.1. The vulnerabilities are severe enough that WordPress enabled forced automatic updates where possible, a measure the project reserves for the worst security flaws.

Advertisements

How many WordPress sites are actually vulnerable?

WordPress's official statistics show more than 400 million sites running the affected versions. But those numbers don't account for sites that have already patched. Cybersecurity consultant Daniel Card sampled roughly 3,500 WordPress sites and found fewer than 15% still running vulnerable code.

Apply that 15% rate across the global WordPress install base and you still get around 90 million exposed sites. Card credited three factors for keeping the number that low: WordPress's automatic update system, Cloudflare blocking attacks at the edge, and sites running web application firewalls.

What attackers can do with these bugs

Security firm Searchlight Cyber discovered one of the critical flaws and named it WP2Shell. Adam Kues, the researcher who reported it to WordPress, found that chaining the two vulnerabilities together gives attackers full remote control of a target site. That means uploading malicious files, modifying content, stealing user data, or using the server to attack other systems.

The attack is not theoretical. All three security firms confirmed hackers are already exploiting these bugs against production websites. The window between patch release and mass exploitation has shrunk to days.

Advertisements

Automattic says its hosted sites were never at risk

Megan Fox, a spokesperson for Automattic, told TechCrunch that all sites on WordPress.com, Pressable, WPVIP, and WP.cloud were protected before the public release. "When the code updates were published, we deployed them immediately across millions of sites," Fox said. The open-source WordPress.org project did not respond to requests for comment.

Self-hosted WordPress installations are the concern. Organizations running WordPress on their own servers, through managed hosting providers like Kinsta, WP Engine, or SiteGround, need to verify their sites are running version 6.9.5 or 7.0.2 or later.

What site operators should do now

Check your WordPress version immediately. If automatic updates are disabled, update manually. If you manage multiple sites, audit all of them. The vulnerable versions are 6.9.0 through 6.9.4 and 7.0.0 to 7.0.1.

  • Confirm you're running WordPress 6.9.5, 7.0.2, or newer
  • Enable automatic updates if you've disabled them
  • Review server logs for signs of compromise
  • Use a web application firewall if you don't already

Sites that were running vulnerable versions and have now patched should still review access logs. If attackers got in before the update, patching won't remove any backdoors they installed.

ℹ️

Logicity's Take

The 90-million-site estimate is alarming, but the real story is how fast the patch-to-exploit window has collapsed. Attackers are now weaponizing WordPress vulnerabilities within days of disclosure, not weeks. For organizations running self-hosted WordPress at scale, this reinforces the case for managed WordPress hosting where patches deploy automatically across fleets. WP Engine starts at $20/month, Kinsta at $35/month, and WordPress.com's business tier at $25/month. The cost of a breach, reputational damage, or SEO penalties from injected spam far exceeds the hosting premium.

Frequently Asked Questions

Which WordPress versions are affected by this vulnerability?

WordPress versions 6.9.0 through 6.9.4 and 7.0.0 to 7.0.1 are vulnerable. Update to 6.9.5, 7.0.2, or later.

How do I check if my WordPress site is vulnerable?

Log into your WordPress admin dashboard and check the version number at the bottom of any admin page. You can also check via the readme.html file in your WordPress root directory.

Will WordPress automatically update my site?

WordPress enabled forced automatic updates for this patch where possible. However, some hosting configurations or security plugins disable auto-updates. Verify your version manually.

What can attackers do if they exploit these bugs?

The two vulnerabilities can be chained to achieve full remote control of a WordPress site, including uploading files, modifying content, stealing data, and using the server for further attacks.

Is WordPress.com affected?

No. Automattic confirmed that WordPress.com, Pressable, WPVIP, and WP.cloud sites were protected before the public patch release.

Also Read
Craneware breach exposes US hospital billing data

Another recent example of security failures affecting millions of users

ℹ️

Need Help Implementing This?

If you're managing multiple WordPress sites and need help auditing your security posture or migrating to managed hosting, reach out to the Logicity team. We can connect you with vetted WordPress security consultants.

Source: TechCrunch / Lorenzo Franceschi-Bicchierai

H

Huma Shazia

Senior AI & Tech Writer

Produced with AI assistance and reviewed by the Logicity editorial team. Learn more in our Editorial Policy.

Related Articles