WordPress users must update as hackers hit 90 million sites

WordPress users must update as hackers hit 90 million sites

Two critical flaws are being abused in the wild, and owners have only a small window to react

Millions of website owners woke up this week to an urgent warning, and ignoring it could hand their entire site to a stranger. WordPress, the software that quietly powers a huge slice of the internet, has been hit by a pair of critical security holes that attackers are already using to hijack sites in real time. Security researchers estimate that tens of millions of pages remain wide open, and the clock is ticking for anyone who has not installed the WordPress fix.

Why the WordPress alarm is ringing so loudly

Last week the team behind the platform rushed out an emergency patch for two severe flaws, urging every user to update without delay. The danger was serious enough that WordPress switched on forced updates wherever it could, a step it rarely takes, and a clear signal of how dangerous the situation had become. Within days, cybersecurity firms including Patchstack, Hexastrike and WatchTowr reported that criminals were exploiting the weaknesses in the wild, meaning live attacks were already sweeping across unpatched pages before many owners even knew a problem existed.


How 90 million sites ended up in the danger zone

The exposure is staggering. The vulnerable builds are versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1, and official figures show more than 400 million WordPress sites once ran that flawed code. A security consultant who sampled roughly 4,200 sites estimated that under 15% were still vulnerable. Stretched across the full population of pages, that share still works out to about 90 million WordPress pages sitting in the crosshairs.

One of the bugs, uncovered by a researcher at a security firm and nicknamed WP2Shell, can be chained with a second flaw to give attackers full remote control of a site. The platform runs an enormous share of the world websites, from tiny hobby blogs to busy online stores, which is exactly why a single weakness can ripple so far and so fast.


What a takeover really means for you

Full remote control is the worst-case scenario for any site owner. Once inside, an intruder can steal data, deface pages, plant harmful code, redirect visitors or lock the rightful owner out entirely. For a small business, a personal blog or a creator who depends on their platform for income, that kind of breach can wipe out years of work overnight and drain the trust of an entire audience in a matter of hours. That is why the warning has spread far beyond the tech world and into the inboxes of everyday WordPress users who may never think of themselves as targets.

How to protect your WordPress site right now

The good news is that the fix is simple, and defenders have already blunted much of the damage. WordPress earned praise for pushing automatic updates, while Cloudflare has been blocking attacks aimed at exposed pages, and sites running a web firewall have largely stayed safe. If you manage a site, here is what matters most.

  • Update to the latest version immediately, since older builds carry the flaws
  • Turn on automatic updates so future patches install on their own
  • Keep a web firewall or a trusted security plugin active at all times
  • Back up your files and database before and after you update

The threat is real, but it is entirely beatable for anyone who chooses to act fast. Every day a site stays on an old build is another day it sits exposed, so the safest move is to log in, check your version and update before attackers find you first. Even sites that look untouched can be quietly compromised, which makes a quick check well worth the few minutes it takes. The companies behind WordPress had not issued further public comment, yet the message from researchers is unmistakable, and treating this as urgent is easily the smartest thing any WordPress owner can do today to keep a site safe.

Source: TechCrunch

Leave a Comment