WordPress has moved quickly to close two critical security flaws, but the latest reports show that some websites are still exposed while attackers attempt to exploit the gaps. The platform urged site owners to update immediately, and forced updates were enabled where possible.
Cybersecurity firms including Patchstack, Hexastrike, and WatchTowr say the vulnerabilities are being targeted in real-world attacks. The affected releases include WordPress 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1, versions that remain widely used across the web.
WordPress' own statistics suggest that more than 400 million websites may still be running these builds, though that figure likely includes sites that have already patched. Independent estimates point to a smaller active risk pool, but still one large enough to affect tens of millions of websites.
Security researcher Daniel Card reviewed a sample of roughly 4,200 WordPress sites and estimated that fewer than 15% were vulnerable. Applied at scale, that would still leave around 90 million sites potentially exposed. WordPress' automatic update system, along with protections from services such as Cloudflare and web application firewalls, is helping reduce the window of risk.
One of the flaws, identified by Searchlight Cyber researcher Adam Kues and named WP2Shell, can be combined with the second bug to give attackers full remote control of an affected site. The episode highlights how fast patch adoption has become a core part of modern web resilience. In the future, faster automated defenses may define the next standard for a safer internet.