Two critical security flaws in WordPress are being actively exploited by hackers to remotely take over websites. A cybersecurity researcher estimates tens of millions of sites could be affected.
The Vulnerability
Two critical bugs in WordPress software have created a window for attackers to gain remote code execution on vulnerable websites. The flaws were recently patched, but hackers are already exploiting unpatched installations.
Scale of Impact
The potential reach is substantial. WordPress powers approximately 43% of all websites globally, making it a prime target. Cybersecurity researchers estimate that tens of millions of websites could be compromised if administrators fail to apply the patches promptly.
Active Exploitation
Attackers are not waiting. Reports indicate active exploitation campaigns targeting websites still running vulnerable versions of WordPress. Once compromised, hackers gain the ability to execute arbitrary code, install malware, steal data, or redirect traffic.
Affected Sites
Small businesses, blogs, e-commerce platforms, and enterprise websites are all potentially at risk. Any WordPress installation that hasn't been updated to the patched version remains vulnerable.
Recommended Actions
WordPress administrators should immediately:
- Update WordPress to the latest patched version
- Update all plugins and themes
- Enable automatic updates if possible
- Review site access logs for suspicious activity
- Consider using security plugins for added protection
Timeline Matters
The window between patch release and widespread exploitation is often narrow. Website owners who delay updates significantly increase their risk of compromise.
This incident underscores the critical importance of timely security patching across web infrastructure. With WordPress powering such a large portion of the internet, vulnerabilities in the platform have immediate, widespread implications.
The US Department of Defense has implemented a policy to disable advertising trackers on military personnel's mobile devices. The measure aims to prevent location data and personal information from being collected and sold by third-party companies.
Identity verification company IDScan faces multiple lawsuits after hackers allegedly accessed and attempted to sell driver's license data for over 153 million individuals.
Attackers are actively exploiting a critical authentication bypass vulnerability in Citrix NetScaler, according to Previdian. CVE-2026-19490 allows threat actors to circumvent security controls on the widely-deployed application delivery platform.
A researcher known as Nightmare Eclipse has disclosed a CrowdStrike Falcon zero-day exploit called FalconFlank that enables privilege escalation on fully patched Windows systems. The vulnerability affects the widely-deployed endpoint protection software.