Hackers exploit two critical WordPress core vulnerabilities, including wp2shell, in the wild; millions of websites at risk of takeover
Daniel CardWordPressPatchstackCloudflareOpenAIwatchTowrSearchlight CyberWatchTowrHadrianAutomatticHexastrike

Hackers exploit two critical WordPress core vulnerabilities, including wp2shell, in the wild; millions of websites at risk of takeover

Hackers are exploiting two critical vulnerabilities in WordPress, including the wp2shell flaw, putting millions of websites at risk of takeover. Cybersecurity firms report that tens of millions of sites remain vulnerable, prompting urgent updates from WordPress to mitigate the threat of unauthorized access.

TechCrunch TechCrunch+2 sources16h ago
CuriousCats Full Story

Hackers are exploiting two critical vulnerabilities in WordPress, including the wp2shell flaw, which allows full remote control of affected websites. Cybersecurity firms estimate that over 90 million websites could be at risk, with tens of millions still running vulnerable versions of the software.19

The vulnerabilities affect WordPress versions 6.9.0 through 6.9.4 and 7.0.0 to 7.0.1. According to WordPress’ official stats, there are more than 400 million websites running these flawed versions, although this number may not reflect recently patched sites. Automattic, the company behind WordPress, has enabled forced updates to mitigate the risks.3710

The wp2shell vulnerability allows attackers to execute arbitrary code without requiring authentication or special configuration. “An attacker who reaches the bug gains unauthenticated code execution on the web server,” researchers noted, emphasizing the potential for complete site takeover.

Cybersecurity consultant Daniel Card analyzed a sample of around 4,200 WordPress websites and projected that 90 million could be vulnerable. “We are already seeing PoC exploits in circulation,” said Benjamin Harris, CEO of watchTowr, highlighting the urgency for website owners to update their systems immediately.

Organizations are advised to upgrade to WordPress versions 6.9.5 or 7.0.2 and to review their deployments to ensure unauthorized access to the REST API is blocked.

Key Insight
“The flaws affect WordPress versions 6.9.0 through 6.9.4 and 7.0.0 to 7.0.1, prompting the WordPress security team to enable forced automatic updates across all affected installations. Within 24 hours, public proof-of-concept exploits emerged on GitHub, and multiple cybersecurity firms have confirmed active exploitation, warning that unauthenticated attackers can achieve full remote code execution.”
CuriousCats studied:
1
TechCrunchTechCrunch
“Hackers are breaking into websites that run vulnerable versions of the popular blogging software WordPress, according to several cybersecurity firms.”
TechCrunch →
2
csoonline.comcsoonline.com
“Organizations running recent versions of WordPress are being asked to patch a newly detailed pre-authentication remote code execution (RCE) vulnerability affecting the platform’s built-in REST Batch API.”
csoonline.com →
3
CyberSecurityNewsCyberSecurityNews
“A critical pre-authentication remote code execution (RCE) vulnerability chain nicknamed “wp2shell” has been disclosed in WordPress Core, putting an estimated 500 million-plus websites at risk of full takeover by completely unauthenticated attackers.”
CyberSecurityNews →
Ask CuriousCats
What are the vulnerabilities in WordPress?
Who developed the wp2shell exploit?
Why are millions of websites vulnerable?
Are there similar vulnerabilities in other platforms?
How quickly have exploits emerged in this case?
Become the most informed
person in the room.
Personal AI agents scanning 100,000+ sources — news, video, and social media — delivered every morning.
Download the App Go to CuriousCats.ai
🇺🇸 US🇮🇳 India🇬🇧 UK🇨🇦 Canada🇸🇬 Singapore
Liked the depth here?
Get the full internet briefed for you any time of the day.
Get CuriousCats