Key Takeaways

- Two critical WordPress vulnerabilities (versions 6.9.0-6.9.4 and 7.0.0-7.0.1) are under active exploitation despite patches released last week
- Security consultant Daniel Card estimates 15% of WordPress sites remain unpatched, translating to roughly 90 million vulnerable websites
- Attackers can achieve full remote control of vulnerable sites by chaining the two bugs together
Hackers are actively breaking into WordPress websites running unpatched software, multiple cybersecurity firms confirmed Monday. Despite WordPress pushing emergency automatic updates last week, an estimated 90 million sites remain vulnerable to two critical bugs that allow complete remote takeover.
Disclosure
Some links in this post are affiliate links — Logicity earns a commission if you sign up, at no extra cost to you. We only link products we have used or actively recommend.
Patchstack, Hexastrike, and WatchTowr have all observed exploitation in the wild since WordPress released patches for versions 6.9.0 through 6.9.4 and 7.0.0 to 7.0.1. The vulnerabilities are severe enough that WordPress enabled forced automatic updates where possible, a measure the project reserves for the worst security flaws.
How many WordPress sites are actually vulnerable?
WordPress's official statistics show more than 400 million sites running the affected versions. But those numbers don't account for sites that have already patched. Cybersecurity consultant Daniel Card sampled roughly 3,500 WordPress sites and found fewer than 15% still running vulnerable code.
Apply that 15% rate across the global WordPress install base and you still get around 90 million exposed sites. Card credited three factors for keeping the number that low: WordPress's automatic update system, Cloudflare blocking attacks at the edge, and sites running web application firewalls.
What attackers can do with these bugs
Security firm Searchlight Cyber discovered one of the critical flaws and named it WP2Shell. Adam Kues, the researcher who reported it to WordPress, found that chaining the two vulnerabilities together gives attackers full remote control of a target site. That means uploading malicious files, modifying content, stealing user data, or using the server to attack other systems.
The attack is not theoretical. All three security firms confirmed hackers are already exploiting these bugs against production websites. The window between patch release and mass exploitation has shrunk to days.
Automattic says its hosted sites were never at risk
Megan Fox, a spokesperson for Automattic, told TechCrunch that all sites on WordPress.com, Pressable, WPVIP, and WP.cloud were protected before the public release. "When the code updates were published, we deployed them immediately across millions of sites," Fox said. The open-source WordPress.org project did not respond to requests for comment.
Self-hosted WordPress installations are the concern. Organizations running WordPress on their own servers, through managed hosting providers like Kinsta, WP Engine, or SiteGround, need to verify their sites are running version 6.9.5 or 7.0.2 or later.
What site operators should do now
Check your WordPress version immediately. If automatic updates are disabled, update manually. If you manage multiple sites, audit all of them. The vulnerable versions are 6.9.0 through 6.9.4 and 7.0.0 to 7.0.1.
- Confirm you're running WordPress 6.9.5, 7.0.2, or newer
- Enable automatic updates if you've disabled them
- Review server logs for signs of compromise
- Use a web application firewall if you don't already
Sites that were running vulnerable versions and have now patched should still review access logs. If attackers got in before the update, patching won't remove any backdoors they installed.
Logicity's Take
The 90-million-site estimate is alarming, but the real story is how fast the patch-to-exploit window has collapsed. Attackers are now weaponizing WordPress vulnerabilities within days of disclosure, not weeks. For organizations running self-hosted WordPress at scale, this reinforces the case for managed WordPress hosting where patches deploy automatically across fleets. WP Engine starts at $20/month, Kinsta at $35/month, and WordPress.com's business tier at $25/month. The cost of a breach, reputational damage, or SEO penalties from injected spam far exceeds the hosting premium.
Frequently Asked Questions
Which WordPress versions are affected by this vulnerability?
WordPress versions 6.9.0 through 6.9.4 and 7.0.0 to 7.0.1 are vulnerable. Update to 6.9.5, 7.0.2, or later.
How do I check if my WordPress site is vulnerable?
Log into your WordPress admin dashboard and check the version number at the bottom of any admin page. You can also check via the readme.html file in your WordPress root directory.
Will WordPress automatically update my site?
WordPress enabled forced automatic updates for this patch where possible. However, some hosting configurations or security plugins disable auto-updates. Verify your version manually.
What can attackers do if they exploit these bugs?
The two vulnerabilities can be chained to achieve full remote control of a WordPress site, including uploading files, modifying content, stealing data, and using the server for further attacks.
Is WordPress.com affected?
No. Automattic confirmed that WordPress.com, Pressable, WPVIP, and WP.cloud sites were protected before the public patch release.
Another recent example of security failures affecting millions of users
Need Help Implementing This?
If you're managing multiple WordPress sites and need help auditing your security posture or migrating to managed hosting, reach out to the Logicity team. We can connect you with vetted WordPress security consultants.
Source: TechCrunch / Lorenzo Franceschi-Bicchierai
Huma Shazia
Senior AI & Tech Writer
Produced with AI assistance and reviewed by the Logicity editorial team. Learn more in our Editorial Policy.
Related Articles
More in Trending Tech
AI Revolution: How Tech is Transforming the World, One Industry at a Time
From desalination plants in Iran to AI-powered manufacturing, the tech world is abuzz with innovation. Discover how AI is changing the game for small entrepreneurs and what it means for the future of industry. Explore the latest developments in cybersecurity, robotics, and more.

Revolutionizing AI: The Game-Changing Tech That's Making Agents Smarter
A new technology is set to revolutionize the way AI agents learn and adapt, enabling them to accumulate wisdom and apply it to new situations. This innovation has the potential to significantly boost the reliability of AI agents, especially in complex tasks. By converting raw agent trajectories into reusable guidelines, this tech is poised to transform the AI landscape.

The Dark Side of AI: How Bots Are Fueling a Monetized Abuse Ecosystem
A recent analysis of 2.8 million Telegram messages reveals a shocking truth: AI-powered bots are being used to create and sell non-consensual intimate images. These bots can turn ordinary photos into synthetic nude images, and the abuse is being monetized through affiliate programs and subscription-based archives. The researchers behind the study are calling for stricter regulations to combat this growing problem.

AI's Secret Sauce: How Journalism Became the Unlikely Ingredient
A recent study reveals that AI chatbots rely heavily on journalistic sources for their quotes, with one in four coming from news outlets. This shocking discovery has significant implications for the media industry and our understanding of AI's information gathering processes. As AI technology continues to evolve, it's essential to consider the role of journalism in shaping its responses.


