Cybersecurity firms have warned that hackers are exploiting vulnerable versions of the popular WordPress blogging software to break into websites, with one estimate putting the number of potentially affected sites in the tens of millions as of Monday.
WordPress last week patched two critical security flaws and urged website operators to update their software “immediately.”
Given the severity of the vulnerabilities, the company enabled forced updates where possible.
Since then, cybersecurity firms Patchstack, Hexastrike and WatchTowr have reported that the flaws are being actively exploited in the wild, with attackers targeting websites that have yet to install the security updates.
The exact number of WordPress-powered websites at risk remains unclear, but available data offers some indication of the scale of the problem. The affected versions are WordPress 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. Official WordPress statistics indicate that more than 400 million websites are running those versions, although the figures may not account for sites that have been patched recently.
Cybersecurity consultant Daniel Card said that his analysis of about 4,200 WordPress websites found that fewer than 15 per cent were vulnerable, according to TechCrunch.
Applying that estimate to the broader WordPress ecosystem would still put the number of potentially affected websites at roughly 90 million.
The researcher credited WordPress’s automatic update system, Cloudflare’s efforts to block attacks against vulnerable sites, and the use of cybersecurity protections such as web application firewalls for helping limit the number of websites currently at risk of being hacked.
Automattic and WordPress.org, the project responsible for developing WordPress’ open-source code, did not immediately respond to requests for comment.

