Two WordPress bugs are putting up to 90 million websites at risk of a full takeover right now

Started by Abbie21, Yesterday at 08:59 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: Two WordPress bugs are putting up to 90 million websites at risk of a full takeover right now   Views(Read 83 times)
Active members in this topic:
Abbie21(1)

Abbie21

Cybersecurity firms including Patchstack, Hexastrike and WatchTowr are warning that hackers are actively exploiting two critical WordPress vulnerabilities in the wild, breaking into and taking over websites that haven't yet updated. WordPress patched both flaws last week and urged immediate updates, treating the issue seriously enough to enable forced automatic updates wherever possible

The vulnerable versions span WordPress 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. According to WordPress's own statistics, more than 400 million websites run those flawed versions, though that figure almost certainly overstates current exposure since it doesn't reflect sites that have already patched. Cybersecurity consultant Daniel Card sampled around 4,200 WordPress sites and estimates fewer than 15 percent remain actually vulnerable, a rate that, applied across the full population of WordPress sites online, still works out to roughly 90 million exposed websites

One of the two flaws, dubbed WP2Shell, was discovered and reported by researcher Adam Kues of cybersecurity firm Searchlight Cyber. Paired together, the two bugs let an attacker take complete remote control of a vulnerable website. Card credited WordPress's forced update push, Cloudflare's active blocking of attacks against vulnerable sites, and web application firewalls on individual sites with limiting how many have actually been compromised so far, even with active exploitation already confirmed

Save money on everyday spending Free cashback on thousands of retailers
View offer