WordPress is facing active cyberattacks targeting security vulnerabilities in versions 6.9.0 through 7.0.1. While the platform is pushing automated updates to protect its massive user base, millions of websites remain at risk of a full remote takeover. Investors should note that widespread security breaches can disrupt operations for businesses relying on the platform for their digital presence.
Millions of websites powered by WordPress are currently at risk following the discovery of two severe security vulnerabilities. The affected software versions include 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. Cybersecurity researchers have confirmed that attackers are actively exploiting these flaws in the wild to gain unauthorized access to unpatched websites.
The scale of the potential impact is significant given that WordPress powers a vast portion of the global web. While official statistics indicate that over 400 million websites utilize these specific versions, security experts estimate that roughly 15% of those sites may still be running unpatched software. This potentially leaves tens of millions of websites worldwide susceptible to a complete remote takeover if site administrators do not manually apply the necessary updates.
The security risk is highlighted by the discovery of a specific bug, referred to as WP2Shell, which was identified by security researcher Adam Kues. This vulnerability, when used alongside a second flaw, allows hackers to bypass standard protections and seize full control of a website. For businesses and e-commerce platforms that rely on WordPress to manage customer data, transactions, or digital services, such a compromise could lead to data theft, service downtime, and reputational damage.
WordPress has initiated a push for automatic updates, and third-party security services such as Cloudflare have implemented defensive measures to block known attack patterns. These actions have mitigated the risk for many users. However, for websites hosted on independent servers without automated management, the responsibility to patch the software lies with the site owners. The primary concern for stakeholders is that any successful mass-scale hack could disrupt digital commerce, lead to loss of intellectual property, or trigger regulatory scrutiny regarding data protection and user privacy. Investors and business owners should ensure that their technical teams have verified that their installations are running the latest, secure versions of the software to prevent operational disruption.
