DMR News

Advancing Digital Conversations

Hackers Exploit Critical WordPress Flaws to Take Control of Vulnerable Websites

ByJolyen

Jul 21, 2026

Hackers Exploit Critical WordPress Flaws to Take Control of Vulnerable Websites

Hackers are exploiting two recently patched vulnerabilities in WordPress to take control of websites that have not installed the latest security updates. The flaws affect WordPress 6.9.0 through 6.9.4 and versions 7.0.0 through 7.0.1, potentially leaving tens of millions of sites exposed.

WordPress released emergency fixes on July 17 and urged website administrators to update immediately. Due to the severity of the flaws, the project also enabled forced automatic updates where possible.

Two Vulnerabilities Can Be Combined

The official WordPress security release addressed one critical vulnerability and another rated as high severity. Patched versions include WordPress 6.8.6, 6.9.5 and 7.0.2.

One flaw, identified as CVE-2026-63030, was discovered by Adam Kues of Searchlight Cyber and named WP2Shell. The vulnerability allows an unauthenticated attacker to execute code remotely on a standard WordPress installation without requiring a vulnerable plugin.

According to Searchlight Cyber’s technical disclosure, attackers can combine WP2Shell with a separate SQL injection flaw to gain complete control of affected websites. Security companies have since reported attempts to exploit both vulnerabilities on unpatched systems.

Millions of Websites May Remain Exposed

WordPress usage statistics indicate that hundreds of millions of websites were running affected software versions before the patches were released. Those figures do not show how many sites have since received automatic or manual updates.

Cybersecurity consultant Daniel Card examined a sample of about 3,500 WordPress sites and estimated that fewer than 15% remained vulnerable. Applying that percentage across the wider WordPress ecosystem would leave an estimated 90 million websites exposed, though the actual number cannot yet be confirmed.

Card credited WordPress’s automatic updates, Cloudflare’s attack blocking and website firewalls with reducing the number of systems that attackers could compromise.

Hosted WordPress Services Already Protected

Automattic said websites hosted through WordPress.com, Pressable, WordPress VIP and WP.cloud partners were protected before the public disclosure. The company said it deployed the updated code across millions of hosted websites once the patches became available.

Administrators running their own WordPress installations should confirm that their sites use version 7.0.2, 6.9.5 or 6.8.6, depending on their release branch. WordPress advises operators not to assume that an automatic update has completed successfully and to verify the installed version through the administration dashboard.


Featured image credits: Wikimedia Commons

For more stories like it, click the +Follow button at the top of this page to follow us.

Jolyen

As a news editor, I bring stories to life through clear, impactful, and authentic writing. I believe every brand has something worth sharing. My job is to make sure it’s heard. With an eye for detail and a heart for storytelling, I shape messages that truly connect.

Leave a Reply

Your email address will not be published. Required fields are marked *