Hackers are actively exploiting critical security vulnerabilities in WordPress that were patched last week, putting millions of websites at risk.Despite WordPress' forced updates for versions 6.9.0 through 6.9.4 and 7.0.0 to 7.0.1, cybersecurity firms report that attackers are still compromising vulnerable sites.Estimates suggest over 400 million websites run the flawed versions, though updated statistics may not reflect recent patches.Daniel Card's analysis of 3,500 sites indicates less than 15% are vulnerable, projecting around 90 million at risk globally.The exploited bugs, dubbed WP2Shell by Searchlight Cyber, allow full remote control of affected sites.
This highlights the ongoing challenge of ensuring widespread adoption of security patches, as many websites remain unpatched despite the severity of the vulnerabilities.The incident underscores the need for better user education and automated update mechanisms to protect against emerging threats.
Original title: Hackers Are Exploiting Recently Patched WordPress Bugs, Putting Millions of Websites at Risk
The AI system has determined that this news is clickbait/sensationalist: : The original title uses sensationalist language like 'Putting Millions of Websites at Risk' to attract attention, which is typical of clickbait headlines. This has coincided with the opinion of the majority of users.