Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk
Two critical security flaws in WordPress’ software have given hackers the chance to remotely take over tens of millions of websites, according to an estimate by a cybersecurity researcher.

Hackers are actively taking advantage of recently fixed WordPress security flaws, exposing millions of websites to possible takeover, according to a cybersecurity researcher cited in a monitored public feed.
The feed summary says two critical bugs in WordPress’ software created an opening for attackers to remotely compromise tens of millions of sites. WordPress, one of the world’s most widely used content management systems, powers a vast share of the internet, which makes security problems in its core software especially sensitive for site owners, developers and hosting providers.
The reported risk centers on flaws that were patched before the public warning, but that may still be present on sites that have not updated. That kind of lag between a fix and widespread adoption is often what gives hackers a window of opportunity. In this case, the concern is not only that the vulnerabilities were severe, but that they could be used remotely, increasing the potential scale of abuse.
The researcher’s estimate, as described in the feed, suggests the number of exposed websites could reach into the tens of millions. The summary does not identify the researcher by name or provide additional technical details about the flaws, but it indicates the issue is already being exploited in the wild.
For website operators, the message is straightforward: software updates matter. Security patches can close dangerous holes, but only if site administrators install them promptly. Delays can leave even small sites vulnerable to attacks that may lead to defacement, malware installation, data theft or loss of control over admin accounts.
The report is based on a monitored public feed and is attributed to TechCrunch. No further details were included in the summary provided to Novexa News, but the warning underscores a familiar pattern in web security: once a high-impact bug becomes public, attackers often move quickly to find unpatched targets.
Site owners using WordPress are typically advised to keep the core platform, plugins and themes updated, limit administrative access where possible and use security monitoring tools to detect suspicious behavior early. In a situation like this, the most important step is confirming that the latest patches are applied across all affected installations.
Source: TechCrunch - https://techcrunch.com/2026/07/20/hackers-are-exploiting-recently-patched-wordpress-bugs-putting-millions-of-websites-at-risk/








