Free NewsletterPro Login

Free Live Investors Workshop

Seats limited

Tue, Sep 29.

The dollar is losing value.

Here’s how investors can still profit.

Hosted By

Jaspreet Singh

Founder, Briefs Finance

X
Free Live Investor Workshop

WP Security Flaws Expose Over 80 Million Sites to Remote Takeover

Published Jul 21, 2026
Share:
Summary:
  • Two critical security vulnerabilities in WordPress versions 6.9.0-6.9.4 and 7.0.0-7.0.1 are being actively exploited, giving attackers full administrative control over unpatched websites.
  • A security consultant's review of roughly 4,200 sites indicates that fewer than 15% remain unpatched, which when extrapolated suggests around 90 million installations are still vulnerable.
  • WordPress issued forced automatic updates for many sites, but Cloudflare's mitigation and delayed patching still leave a large portion of the web at risk.

The Vulnerability and the Attack

Two critical security holes were fixed by WordPress last week, and the organization urged everyone operating the platform to apply the patch right away, with a spokesperson describing the patch as "an immediate action" in a statement. Due to the gravity of these flaws, WordPress implemented automatic forced updates for as many sites as it could. Following the patch, security firms Patchstack, Hexastrike, and WatchTowr reported that attackers are actively exploiting the flaws, seizing control of sites that haven't updated their WordPress installation.

The affected releases include WordPress 6.9.0 through 6.9.4, as well as 7.0.0 to 7.0.1. Adam Kues, a researcher at Searchlight Cyber, discovered one of these critical flaws and named it WP2Shell. When combined with the second vulnerability, attackers gain complete remote access to any susceptible site.

Official WordPress data indicates that more than 400 million websites are still on the vulnerable versions, though that number probably doesn't account for sites that have been patched since. Consultant Daniel Card informed TechCrunch that after examining roughly 4,200 WordPress sites, he estimates that less than one in six remain unpatched. Extrapolating Card's estimate to the entire WordPress ecosystem yields approximately 90 million at-risk sites.

Card commended WordPress's forced-update system and also noted that Cloudflare has been successfully blocking attacks on sites that haven't been patched. Neither Automattic nor WordPress.org, the entity behind the open-source project, responded to requests for comment in time.

Get the market news that matters in a five-minute read with Market Briefs, our free daily newsletter

The diversity of WordPress installations complicates patching efforts. Many site administrators disable automatic updates to preserve compatibility with custom themes or plugins, while some hosting environments block WordPress's forced-update mechanism. This leaves a substantial number of sites exposed, even as Cloudflare helps mitigate attacks on unpatched systems.

Given that WordPress powers over 40% of all websites, the scale of the threat is enormous. Site owners who neglect updates risk losing control of their content, user data, and even their domain.

The widespread reliance on WordPress makes these vulnerabilities particularly dangerous. Many site owners are small businesses or individuals without dedicated security teams, making them slow to apply updates. Additionally, the forced-update mechanism, while effective for many, cannot reach sites hosted on environments that block it or those running heavily customized installations. This patchwork of security practices means that even weeks after a fix, a significant portion of the web remains exposed.

How Many Sites Are Still at Risk

The exact number of vulnerable WordPress sites is unknown, though reasonable estimates can be drawn.

The Broader Impact on the Web

Beyond the immediate threat to individual sites, these vulnerabilities highlight a systemic risk across the internet. Because WordPress runs nearly half of all websites - from personal blogs to large e-commerce stores - a single unpatched flaw can cascade. Attackers who compromise one vulnerable site may use it as a launchpad to target others on shared hosting servers, or to steal credentials and sensitive user data.

The forced-update system, while a powerful tool, depends on hosting providers and site owners cooperating. When Cloudflare blocks attack traffic, it buys time, but does not eliminate the need for site operators to patch their installations. The real solution remains a global, coordinated update effort - something that has historically been difficult to achieve given the fragmented nature of WordPress hosting.

Join Market Briefs, our free daily newsletter, for a quick daily rundown of the markets

Disclosure

Recent News

1 2 3 78

Get Market Briefs delivered to your inbox every morning for free!

No fluff. No noise. No politics. Just finance news you can read in 5 minutes.
0 Shares
Share via
Copy link