Opinion: WordPress Flaws Expose a Fragile Ecosystem

AI-generated image · Bay Street Wire
Critical vulnerabilities leave millions of websites at risk.
As TechCrunch first reported, hackers are currently exploiting two critical security flaws in WordPress, allowing for full remote control of vulnerable sites. One of these bugs, identified by Adam Kues of Searchlight Cyber as "WP2Shell," is particularly devastating. While WordPress.org and Automattic did not immediately respond to a request for comment, WordPress has urged immediate updates and implemented forced updates where possible to combat the threat.
The scale of the risk is staggering. TechCrunch notes that official statistics show over 400 million websites running flawed versions (specifically 6.9.0 through 6.9.4 and 7.0.0 to 7.0.1). While cybersecurity consultant Daniel Card suggests less than 15% of a 4,200-site sample were vulnerable, applying that ratio to the total population still leaves roughly 90 million websites at risk. Other cybersecurity firms, including Patchstack, Hexastrike, and WatchTowr, have confirmed these exploits are active in the wild.
While Cloudflare has stepped in to block some attacks and web firewalls provide a layer of defense, the burden of security remains squarely on the site owner.

