The Vulnerability and the Attack
Two critical security holes were fixed by WordPress last week, and the organization urged everyone operating the platform to apply the patch right away, with a spokesperson describing the patch as "an immediate action" in a statement. Due to the gravity of these flaws, WordPress implemented automatic forced updates for as many sites as it could. Following the patch, security firms Patchstack, Hexastrike, and WatchTowr reported that attackers are actively exploiting the flaws, seizing control of sites that haven't updated their WordPress installation.
The affected releases include WordPress 6.9.0 through 6.9.4, as well as 7.0.0 to 7.0.1. Adam Kues, a researcher at Searchlight Cyber, discovered one of these critical flaws and named it WP2Shell. When combined with the second vulnerability, attackers gain complete remote access to any susceptible site.
Official WordPress data indicates that more than 400 million websites are still on the vulnerable versions, though that number probably doesn't account for sites that have been patched since. Consultant Daniel Card informed TechCrunch that after examining roughly 4,200 WordPress sites, he estimates that less than one in six remain unpatched. Extrapolating Card's estimate to the entire WordPress ecosystem yields approximately 90 million at-risk sites.
Card commended WordPress's forced-update system and also noted that Cloudflare has been successfully blocking attacks on sites that haven't been patched. Neither Automattic nor WordPress.org, the entity behind the open-source project, responded to requests for comment in time.
Get the market news that matters in a five-minute read with Market Briefs, our free daily newsletter
The diversity of WordPress installations complicates patching efforts. Many site administrators disable automatic updates to preserve compatibility with custom themes or plugins, while some hosting environments block WordPress's forced-update mechanism. This leaves a substantial number of sites exposed, even as Cloudflare helps mitigate attacks on unpatched systems.
Given that WordPress powers over 40% of all websites, the scale of the threat is enormous. Site owners who neglect updates risk losing control of their content, user data, and even their domain.
The widespread reliance on WordPress makes these vulnerabilities particularly dangerous. Many site owners are small businesses or individuals without dedicated security teams, making them slow to apply updates. Additionally, the forced-update mechanism, while effective for many, cannot reach sites hosted on environments that block it or those running heavily customized installations. This patchwork of security practices means that even weeks after a fix, a significant portion of the web remains exposed.
How Many Sites Are Still at Risk
The exact number of vulnerable WordPress sites is unknown, though reasonable estimates can be drawn.
The Broader Impact on the Web
Beyond the immediate threat to individual sites, these vulnerabilities highlight a systemic risk across the internet. Because WordPress runs nearly half of all websites - from personal blogs to large e-commerce stores - a single unpatched flaw can cascade. Attackers who compromise one vulnerable site may use it as a launchpad to target others on shared hosting servers, or to steal credentials and sensitive user data.
The forced-update system, while a powerful tool, depends on hosting providers and site owners cooperating. When Cloudflare blocks attack traffic, it buys time, but does not eliminate the need for site operators to patch their installations. The real solution remains a global, coordinated update effort - something that has historically been difficult to achieve given the fragmented nature of WordPress hosting.
Join Market Briefs, our free daily newsletter, for a quick daily rundown of the markets
