top of page

WordPress Urges Immediate Updates After Critical Security Flaws Exploited

Writer: By The Financial District
By The Financial District
Jul 28
1 min read

WordPress is urging website owners to update their installations immediately after hackers began exploiting newly discovered security vulnerabilities.


WordPress users are being urged to install critical security updates immediately to prevent cyberattacks. [Photo: WordPress Facebook]
WordPress users are being urged to install critical security updates immediately to prevent cyberattacks. [Photo: WordPress Facebook]

The world's leading content management system patched two critical vulnerabilities last week and enabled automatic security updates because of the severity of the flaws, Andrew Nusca reported for Fortune Tech.


The vulnerabilities, collectively referred to as "WP2Shell," affect WordPress versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1.



According to cybersecurity researchers, attackers can exploit the flaws without authentication on default WordPress installations.


Searchlight Cyber said: "The attack has no preconditions and can be exploited by an anonymous user in a stock install of WordPress with no plugins."

SOCRadar reported that Patchstack had recorded active exploitation attempts, while Hexastrike observed attacks through its honeypot systems during the weekend of July 18–19. WatchTowr also reported seeing exploitation attempts in the wild.



WordPress is estimated to power about 43% of all websites worldwide, or roughly 500 million websites, significantly more than competing platforms such as Shopify, Squarespace, and Wix.


According to WordPress' own update tracking tool, approximately three out of four WordPress websites remain vulnerable because they have not yet installed the security update.








TFD (Facebook Profile) (1).png
TFD (Facebook Profile) (3).png

Register for News Alerts

  • LinkedIn
  • Instagram
  • X
  • YouTube

Thank you for Subscribing

The Financial District®  2023

bottom of page