Bỏ qua đến nội dung chính
Back to home
Tech 3 min read

Millions of WordPress Websites Face Remote Takeover Risk by Hackers 🛡️

Critical security flaws recently patched in WordPress are being actively exploited by hackers, threatening tens of millions of websites that have not yet updated.

Tier 1 · sources 83% confidence Auto-priority
Sources techcrunch.com

According to reports from multiple cybersecurity firms on July 20, 2026, hackers are actively exploiting two critical security vulnerabilities in the WordPress platform to take control of unpatched websites. Although WordPress has urgently released a patch and forced automatic updates where possible, the actual scope of impact remains massive due to the large number of vulnerable websites still online. This security incident serves as a major wake-up call for the global web administration community as millions of systems face potential compromise.

Diễn biến chi tiết

Last week, the WordPress organization officially released version 7.0.2 to fix two critical security bugs, urging users to immediately update their systems. Recognizing the severity of the issue, the developer even triggered forced automatic updates for eligible installations. However, according to prominent security firms Patchstack, Hexastrike, and WatchTowr, hackers were faster, launching active exploitation campaigns targeting websites that have not yet upgraded.

Currently, the vulnerable WordPress versions include 6.9.0 through 6.9.4, and 7.0.0 to 7.0.1. Official WordPress statistics show that over 400 million websites run these flawed versions, though the actual number of exposed sites may be lower due to automatic patching. Cybersecurity consultant Daniel Card analyzed a sample of approximately 4,200 WordPress websites and estimated that at least 15% remain vulnerable. Applying this projection across the web, the number of exposed websites still stands at around 90 million.

Phân tích kỹ thuật & Công nghệ

Delving into the technical details, one of the most critical bugs was discovered and reported by researcher Adam Kues of cybersecurity firm Searchlight Cyber. Dubbed "WP2Shell", this vulnerability targets the authentication and file management mechanisms of the core system. When paired with the second vulnerability, attackers can easily bypass standard security checkpoints to execute remote code.

This exploit chain allows hackers to gain full remote code execution (RCE) control over the web server without requiring admin credentials. Consequently, they can install spyware, steal user databases, or turn victim websites into distribution channels for ransomware. This sophisticated combination makes it one of the most dangerous exploit chains to hit the open-source WordPress core in recent years.

Ý kiến chuyên gia & Nhận định

Cybersecurity analysts have praised the swift response of the WordPress development team in pushing forced updates to compatible servers. Expert Daniel Card noted that proactive defense measures, including Cloudflare's rapid deployment of rules to block attack traffic at the network level, have significantly mitigated the number of successfully compromised sites. Nevertheless, experts from Patchstack warn that web application firewalls (WAF) are only temporary workarounds and cannot replace fundamental patching at the source code level.

Tác động & Tương lai

This incident once again highlights the security challenges facing open-source content management systems (CMS) that power much of the modern web. For businesses and individuals operating websites in Vietnam, proactively auditing WordPress versions and deploying additional defense layers like WAF or multi-factor authentication is critical to securing digital assets. Looking ahead, automated AI-driven attacks are expected to further shrink the window between patch release and active wild exploitation.