Hackers exploiting recently patched WordPress bugs, websites at risk

smurda1 pts0 comments

Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk | TechCrunch

SearchSubmit

Site Search Toggle

Mega Menu Toggle

Topics

Latest

AI

Amazon

Apps

Biotech & Health

Climate

Cloud Computing

Commerce

Crypto

Enterprise

EVs

Fintech

Fundraising

Gadgets

Gaming

Google

Government & Policy

Hardware

Instagram

Layoffs

Media & Entertainment

Meta

Microsoft

Privacy

Robotics

Security

Social

Space

Startups

TikTok

Transportation

Venture

More from TechCrunch

Staff

Events

Startup Battlefield

StrictlyVC

Newsletters

Podcasts

Videos

Partner Content

TechCrunch Brand Studio

Crunchboard

Contact Us

Image Credits: TechCrunch

Security

Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk

Lorenzo Franceschi-Bicchierai

8:35 AM PDT · July 20, 2026

Hackers are breaking into websites that run vulnerable versions of the popular blogging software WordPress, according to several cybersecurity firms. One estimate puts the number of vulnerable WordPress websites at tens of millions as of Monday.

Last week, WordPress patched two critical security flaws, urging people who run its software on their websites to update it “immediately.” The vulnerabilities are so severe that WordPress enabled forced updates where possible. Since then, cybersecurity companies Patchstack, Hexastrike, and WatchTowr have all warned that hackers are exploiting the vulnerabilities in the wild, meaning they are taking over websites that are still running susceptible versions of WordPress.

It’s unclear how many WordPress-powered websites on the internet are at risk, but it’s possible to make some educated guesses. The vulnerable versions of WordPress are 6.9.0 through 6.9.4, and 7.0.0 to 7.0.1. According to WordPress’ official stats, there are more than 400 million websites that run those flawed versions, although these statistics likely don’t reflect websites that have recently been patched.

Cybersecurity consultant Daniel Card, who told TechCrunch that he looked at a sample of around 3,500 WordPress websites, estimates that less than 15% are vulnerable. Applying Card’s projection across the total population of WordPress websites on the internet, the total figure would still be around 90 million.

The researcher credited WordPress with pushing automatic updates, Cloudflare with blocking attacks against vulnerable websites, and websites using cybersecurity protections such as web firewalls for the limited number of sites that could currently be hacked.

WordPress.org, the project that develops WordPress’ open source code, did not immediately respond to a request for comment. Megan Fox, a spokesperson for Automattic, the company that runs WordPress.com and contributes to the open source project, told TechCrunch that "all sites hosted by Automattic, including WordPress.com, Pressable, WPVIP, and WP.cloud partners, were protected even before the release. When the code updates were published, we deployed them immediately across millions of sites."

One of the critical WordPress bugs was found and reported by Adam Kues of cybersecurity firm Searchlight Cyber, which dubbed it WP2Shell. Paired with the other bug, hackers can take full remote control of vulnerable websites.

Topics

bugs, cybersecurity, hackers, hacking, Security, WordPress

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Lorenzo Franceschi-Bicchierai

Senior Reporter, Cybersecurity

Lorenzo Franceschi-Bicchierai is a Senior Writer at TechCrunch, where he covers hacking, cybersecurity, surveillance, and privacy.

You can contact or verify outreach from Lorenzo by emailing lorenzo@techcrunch.com, via encrypted message at +1 917 257 1382 on Signal, and @lorenzofb on Keybase/Telegram.

View Bio

October 13 – 15

San Francisco

Scale faster. Grow your portfolio. Gain practical expertise. No matter your goal, Disrupt can empower you.

Save up to $330 toda y!

REGISTER NOW

Most Popular

Judge pauses $110B Paramount-Warner Bros. merger

Aisha Malik

Apple and Google ordered to purge ‘nudify’ apps from App Stores

Lucas Ropek

Coca-Cola suspended production at its Fairlife dairy after a ransomware attack

Zack Whittaker

Tesla driver in fatal Texas crash pressed accelerator 100%, NTSB confirms

Sean O'Kane

Amid hardware legal battle, OpenAI releases a $230 keyboard for Codex

Lucas Ropek

Microsoft patches bug in video game Age of Empires II

Lorenzo Franceschi-Bicchierai

Anthropic, Blackstone bet the next trillion-dollar AI business is implementation, not just models

Rebecca Bellan

Loading the next article

Error loading the next article

© 2026 TechCrunch Media LLC.

wordpress websites techcrunch cybersecurity hackers lorenzo

Related Articles