Millions of WordPress websites at risk as hackers exploit critical flaws
- Jul 21
- 1 min read
Hackers are actively exploiting two critical vulnerabilities in WordPress, putting potentially tens of millions of websites at risk, according to cybersecurity researchers.
WordPress recently patched the flaws and urged users to update immediately. The vulnerabilities affect versions 6.9.0–6.9.4 and 7.0.0–7.0.1. One of the flaws, dubbed WP2Shell by Searchlight Cyber, can be combined with another vulnerability to allow unauthenticated attackers to execute arbitrary code and potentially gain full control of affected websites.
The flaws are particularly serious because they affect the WordPress core, meaning even sites without vulnerable plugins or themes can be targeted.
Cybersecurity consultant Daniel Card, who analyzed about 4,200 WordPress websites, estimates that fewer than 15% remain vulnerable. Applied to the broader WordPress ecosystem, that could mean roughly 90 million websites are potentially exposed.
Security firms including Patchstack, Hexastrike, and WatchTowr have already reported exploitation attempts. Researchers also say working proof-of-concept exploits appeared online within days of the patches being released.
Administrators should verify that their websites are running WordPress 6.9.5, 7.0.2, or later rather than relying solely on automatic updates. If an immediate update is impossible, temporarily restricting access to /wp-json/batch/v1 through a web application firewall can provide additional protection.
These mitigations are only temporary, however. Website owners should install the latest WordPress security updates as soon as possible.



