Hackers exploit patched WordPress flaws, endangering millions of sites
WordPress, the world’s most popular content‑management system, is now facing a serious security threat after two critical vulnerabilities were discovered that could allow attackers to remotely take over websites. According to estimates by a cybersecurity researcher, the flaws could expose tens of millions of sites that run on the platform, potentially enabling malicious code execution, data theft, or full site hijacking.
The vulnerabilities, which were identified in the core WordPress codebase, allow an attacker to bypass authentication checks and inject arbitrary commands. WordPress has acknowledged the issue and released patches in its latest update cycle, urging site owners to apply the fixes immediately. Security teams are also monitoring for signs of exploitation, and several hosting providers have begun recommending the update as a priority.
Site administrators are advised to review their current WordPress installations, verify that the latest security patches are applied, and consider additional protective measures such as web application firewalls and regular vulnerability scans. Prompt action is essential to mitigate the risk posed by these newly disclosed flaws and to protect the vast number of websites that rely on WordPress for their online presence.