Hackers are exploiting security flaws in vulnerable versions of WordPress, compromising millions of websites worldwide, according to cybersecurity firms. Despite urgent patches, the number of affected sites remains high, with estimates suggesting around 90 million remain at risk.
WordPress versions 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1 are particularly vulnerable, despite updates enabling forced software upgrades. Cybersecurity companies warn that attackers are already exploiting these vulnerabilities, highlighting the urgency of updating WordPress installations.
The situation is compounded by the vast number of websites running outdated versions of the popular blogging platform. While some security measures offer limited protection, it remains a significant challenge to ensure all sites are fully secure.
Cybersecurity expert Daniel Card suggests that fewer than 15% of WordPress sites could be vulnerable. However, with over 400 million websites powered by these versions, the total number at risk still numbers in the tens of millions.
Automattic and other security partners have implemented measures to mitigate the threat, but the scale remains daunting. The incident underscores the ongoing need for vigilance and regular updates across digital platforms.







