1 month ago

WP2Shell Exploit Threatens Millions of WordPress Sites

WP2Shell Exploit Threatens Millions of WordPress Sites
'WP2Shell' exploit sparks fresh warnings for millions of WordPress websites · firstpost.com

There's a big problem with WordPress websites.

Hackers are trying to take advantage of a security flaw called WP2Shell.

This flaw, along with another one, can let hackers take control of websites that haven't been updated.

WordPress has fixed these problems and is automatically updating websites to protect them.

Even so, up to 90 million websites might still be at risk.

Experts say that fewer than 15% of WordPress sites are vulnerable, thanks to automatic updates and other security measures.

It's important for website owners to update their WordPress installations to stay safe.

Key facts

Vulnerable Versions
WordPress 6.9.0 through 6.9.4 and WordPress 7.0.0 through 7.0.1
Estimated Vulnerable Sites
Up to 90 million
Discoverer of WP2Shell
Adam Kues of Searchlight Cyber
Cybersecurity Firms Involved
Patchstack, Hexastrike, watchTowr
Researcher Analyzing Vulnerabilities
Daniel Card

Sources

Related news