Novexa News

Hackers Exploit Recently Patched WordPress Bugs, Putting Millions of Sites at Risk

Two critical security flaws in WordPress' software are giving hackers the chance to remotely take over tens of millions of websites, according to an estimate from a cybersecurity research firm.

TechCrunchPublished July 20th, 2026 3:35 PMUpdated August 24th, 2026 7:00 PM3 min read
Hackers Exploit Recently Patched WordPress Bugs, Putting Millions of Sites at Risk

Millions of websites running one of the internet's most widely used publishing platforms are suddenly facing a genuinely serious security threat, as hackers move quickly to exploit vulnerabilities before site owners can apply the available fix.

The Vulnerabilities Themselves

Two critical security flaws in WordPress' software are giving hackers the chance to remotely take over affected websites, according to an estimate from a cybersecurity research firm putting the number of potentially vulnerable sites in the tens of millions. Critical-severity vulnerabilities that enable remote takeover represent about as serious a security threat as exists in web infrastructure, since successful exploitation can hand attackers complete control over an affected website without requiring any direct physical or credentialed access.

Why "Recently Patched" Doesn't Mean Safe

Despite these specific bugs having been recently patched, meaning a fix is available, hackers are actively exploiting them right now, exploiting the well-documented gap between when a security patch becomes available and when the actual population of affected websites gets around to installing it. That patch-adoption gap is exactly what attackers race to exploit, since a newly disclosed vulnerability combined with a published fix effectively hands malicious actors a detailed roadmap for attacking any site that has not yet applied the update.

Why WordPress's Massive Scale Makes This So Significant

WordPress powers a substantial share of all websites globally, making any critical vulnerability affecting its core software a genuinely significant internet-wide security event rather than a narrow, contained issue affecting a small number of sites. The tens of millions of potentially affected websites estimate reflects just how enormous WordPress's install base actually is, and how much collective exposure exists whenever a critical vulnerability in its core software goes unpatched across even a fraction of that massive user base.

Who Is Most At Risk

Website operators who have not yet applied the available security patches, whether due to unfamiliarity with the vulnerability, delayed update schedules, or simply not yet being aware a patch exists, represent the population most immediately exposed to exploitation attempts already underway. Smaller website operators without dedicated IT or security staff monitoring for exactly this kind of urgent patch notification are often the slowest to apply critical updates, making them disproportionately vulnerable during exactly this kind of active exploitation window.

What Site Owners Need To Do

WordPress site operators need to verify their installations have received the available security patches immediately, given that active exploitation is already underway rather than merely a theoretical future risk. Delaying that update meaningfully increases the risk of an affected site being compromised, particularly given how widely publicized both the vulnerabilities and their active exploitation have become, information that is just as available to potential attackers scanning for unpatched targets as it is to site operators trying to protect themselves.

What Comes Next

Cybersecurity researchers will likely continue monitoring the scale of active exploitation as the patch adoption rate across WordPress's massive install base gradually increases, tracking how quickly the population of vulnerable, unpatched sites shrinks over the coming days and weeks. This incident is also likely to reinforce ongoing calls within the web development community for more automated, faster security update adoption mechanisms, given how consistently the gap between patch availability and widespread adoption continues to create exactly this kind of large-scale exploitation opportunity.

Comments

No approved comments yet.

Related Articles