logo

Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk

ID: aea8b576-2afa-5aad-bb01-658318660abc

STIX ID: report--aea8b576-2afa-5aad-bb01-658318660abc

Feed Name: TechCrunch Security News

Threat Score
85/100

Date Published: 2026-07-20

Date Updated: 2026-07-23

Author: Lorenzo Franceschi-Bicchierai

...
...

Multiple cybersecurity firms reported active exploitation of two critical WordPress vulnerabilities (versions 6.9.0–6.9.4 and 7.0.0–7.0.1) that can allow full remote control of sites when combined (one tracked as WP2Shell). WordPress issued forced updates and vendors like Cloudflare and Automattic deployed protections, but estimates suggest tens of millions of sites could have been vulnerable before patching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.