WordPress repaired two high-risk security gaps last week and urged website operators to update them immediately. Owing to the magnitude of the problem, the Platform has also initiated mandatory updates to the extent feasible. However, security companies have subsequently indicated that hackers have begun to use these loopholes to attack unupgraded websites.

Security agencies issued warnings

Patchstack, Hexastrike and WatchTowr all stated that the relevant loopholes had been exploited in the real attack. This means that the sites of the affected version are still in operation and may be taken over directly by the attackers.

TechCrunch refers to public information that the risk version includes WordPress 6.9.0 to 6.9.4, and 7.0.0 to 7.0.1. According to WordPress official statistics, the total number of websites operating these versions exceeds 400 million. However, this figure may not reflect in a timely manner the recently updated sites.

Sample estimates still point to large-scale exposure.

Following the observation of some 4,200 WordPress sites by network security consultant Daniel Card, it is estimated that the proportion of sites still at risk may be below 15 per cent. Even with this percentage, there may still be about 9 million websites in an attackable state worldwide.

This estimate also indicates that, while automatic updating has reduced the level of risk, the number of websites that have not been upgraded is still small. For sites that rely on WordPress operations, store or business pages, the gap window period continues.

Auto-updates and protections are compressing risk

Daniel Card argued that the number of websites that could be directly breached was not higher because of security measures such as WordPress ' promotion of automatic updates, Cloudflare ' s interception of attacks on leak sites, and the deployment of Web firewalls to some sites.

One of the high-risk loopholes was discovered and reported by Adam Kues, a researcher at Seachlight Cyber, named WP2Shell. It was mentioned that if used in conjunction with another loophole, the attackers could gain complete remote control over the affected website.