- Hackers are breaking into websites that run vulnerable versions of the popular blogging software WordPress, according to several cybersecurity firms.
- One estimate puts the number of vulnerable WordPress websites at tens of millions as of Monday.
- The vulnerabilities are so severe that WordPress enabled forced updates where possible.
- Public proof-of-concept exploits began circulating on GitHub within roughly 24 hours.
- Cybersecurity companies Patchstack, Hexastrike, and WatchTowr reported that hackers are exploiting the vulnerabilities in the wild.
- The vulnerable versions of WordPress are 6.9.0 through 6.9.4, and 7.0.0 to 7.0.1.
- According to WordPress’ official stats, there are more than 400 million websites that run those flawed versions.
- A critical pre-authentication remote code execution (RCE) vulnerability chain nicknamed wp2shell has been disclosed in WordPress Core.
- The flaw, dubbed wp2shell, enables attackers to execute arbitrary code against a default WordPress installation without requiring plugins, authentication, or special configuration.
- The issue affects WordPress 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1.
Hackers are exploiting two critical vulnerabilities in WordPress, including the wp2shell flaw, which allows full remote control of affected websites. Cybersecurity firms estimate that over 90 million websites could be at risk, with tens of millions still running vulnerable versions of the software.19
The vulnerabilities affect WordPress versions 6.9.0 through 6.9.4 and 7.0.0 to 7.0.1. According to WordPress’ official stats, there are more than 400 million websites running these flawed versions, although this number may not reflect recently patched sites. Automattic, the company behind WordPress, has enabled forced updates to mitigate the risks.3710

The wp2shell vulnerability allows attackers to execute arbitrary code without requiring authentication or special configuration. “An attacker who reaches the bug gains unauthenticated code execution on the web server,” researchers noted, emphasizing the potential for complete site takeover.

Cybersecurity consultant Daniel Card analyzed a sample of around 4,200 WordPress websites and projected that 90 million could be vulnerable. “We are already seeing PoC exploits in circulation,” said Benjamin Harris, CEO of watchTowr, highlighting the urgency for website owners to update their systems immediately.
Organizations are advised to upgrade to WordPress versions 6.9.5 or 7.0.2 and to review their deployments to ensure unauthorized access to the REST API is blocked.
“The flaws affect WordPress versions 6.9.0 through 6.9.4 and 7.0.0 to 7.0.1, prompting the WordPress security team to enable forced automatic updates across all affected installations. Within 24 hours, public proof-of-concept exploits emerged on GitHub, and multiple cybersecurity firms have confirmed active exploitation, warning that unauthenticated attackers can achieve full remote code execution.”
