logo

Hackers Exploit Critical WordPress Vulnerabilities, Millions at Risk

ID: c6c29e3e-7b59-586a-88b1-fdbc8167d7bf

STIX ID: report--c6c29e3e-7b59-586a-88b1-fdbc8167d7bf

Feed Name: ThreatCluster

Threat Score
90/100

Date Published: 2026-07-20

Date Updated: 2026-07-20

...
...

Cybersecurity firms report active exploitation of two critical unauthenticated remote code execution vulnerabilities in WordPress (one identified as WP2Shell). Patches are available (WordPress 6.8.6, 6.9.5, 7.0.2) but an estimated ~90 million sites may remain vulnerable; attacks have been observed against versions 6.9.0–6.9.4 and 7.0.0–7.0.1. Site owners are urged to update immediately; partial protections exist via services like Cloudflare and Wordfence Premium.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.