1 month ago
WP2Shell Exploit Threatens Millions of WordPress Sites
There's a big problem with WordPress websites.
Hackers are trying to take advantage of a security flaw called WP2Shell.
This flaw, along with another one, can let hackers take control of websites that haven't been updated.
WordPress has fixed these problems and is automatically updating websites to protect them.
Even so, up to 90 million websites might still be at risk.
Experts say that fewer than 15% of WordPress sites are vulnerable, thanks to automatic updates and other security measures.
It's important for website owners to update their WordPress installations to stay safe.
Hackers are targeting WordPress websites with the WP2Shell exploit.
Up to 90 million WordPress sites could be vulnerable.
WordPress has patched the vulnerabilities and enabled automatic updates.
Cybersecurity firms warn that attackers are already exploiting the flaws.
Automatic updates and security measures have reduced the number of vulnerable sites.
- Who
- Millions of WordPress website owners and cybersecurity firms
- What
- A critical security vulnerability dubbed WP2Shell is threatening WordPress websites
- Where
- Globally, affecting WordPress websites
- When
- After WordPress patched the vulnerabilities and urged immediate updates
- Why
- To prevent attackers from gaining complete remote control of vulnerable websites
Cybersecurity Firms
WordPress Developers
Vulnerability Severity
Cybersecurity Firms
Cybersecurity firms warn that the WP2Shell exploit is highly severe and actively being exploited.
WordPress Developers
WordPress has patched the vulnerabilities and enabled automatic updates to mitigate the risk.
Key facts
- Vulnerable Versions
- WordPress 6.9.0 through 6.9.4 and WordPress 7.0.0 through 7.0.1
- Estimated Vulnerable Sites
- Up to 90 million
- Discoverer of WP2Shell
- Adam Kues of Searchlight Cyber
- Cybersecurity Firms Involved
- Patchstack, Hexastrike, watchTowr
- Researcher Analyzing Vulnerabilities
- Daniel Card







