Key Takeaways
- Hackers are exploiting newly patched vulnerabilities in WordPress.
- Estimates suggest tens of millions of sites remain at risk.
- Automatic updates have been implemented to mitigate attacks.
- Cybersecurity firms are actively monitoring the situation.
Widespread Vulnerability
Cybersecurity experts report that hackers are actively breaking into websites running outdated versions of WordPress. As of Monday, estimates indicate that the number of vulnerable sites could be in the tens of millions.
Recent Security Flaws
Last week, WordPress addressed two significant security issues, urging users to update their software immediately. The severity of these vulnerabilities prompted WordPress to implement forced updates where feasible. Following this, cybersecurity firms such as Patchstack, Hexastrike, and WatchTowr have alerted users that these vulnerabilities are being exploited, allowing hackers to take control of affected websites.
Estimating the Risk
While the exact number of at-risk WordPress sites is uncertain, estimates can be made based on the versions affected. The vulnerable versions include 6.9.0 through 6.9.4 and 7.0.0 to 7.0.1. According to WordPress statistics, over 400 million websites operate on these flawed versions, although this figure may not account for sites that have recently updated.
Consultant Insights
Daniel Card, a cybersecurity consultant, analyzed a sample of approximately 3,500 WordPress sites and found that less than 15% were vulnerable. If this percentage is applied to the total number of WordPress sites globally, the number of potentially compromised sites could still reach around 90 million.
Mitigation Efforts
Card acknowledged the proactive measures taken by WordPress, including automatic updates, and highlighted the role of Cloudflare in blocking attacks on vulnerable sites. Websites employing cybersecurity measures, such as web firewalls, have also contributed to limiting the number of sites that could be hacked.
Response from WordPress
WordPress.org, the organization behind the open-source project, did not respond to requests for comment. However, Megan Fox, a spokesperson for Automattic, which operates WordPress.com, stated that all sites hosted by Automattic were protected even before the updates were released. Upon the publication of the code updates, they were deployed across millions of sites immediately.
Details of the Vulnerabilities
One of the critical vulnerabilities, identified by Adam Kues from Searchlight Cyber, has been labeled WP2Shell. When combined with another bug, it allows hackers to gain full remote control of affected websites.
