Several cybersecurity firms have warned that hackers are attacking popular blogging software running vulnerabilitiesWordPresswebsite. According to preliminary estimates by a security agency on Monday, there are still tens of millions of people around the world.WordPressThe website is at high risk.

last week,WordPress officially releases patches for two critical security vulnerabilities, and strongly urges all website administrators to update their software “immediately.” Due to the extremely harmful nature of the vulnerability, officials have even enabled a forced update mechanism when conditions permit. However, several cybersecurity companies, including Patchstack, Hexastrike, and WatchTowr, have since issued warnings that hackers are actively exploiting these vulnerabilities "in the wild" and taking over vulnerable websites that have not yet completed updates.

At present, it is difficult to accurately count the number of affected websites, but the outside world has been able to make preliminary guesses. It is reported that there are loopholes in theWordPressThe versions mainly cover versions 6.9.0 to 6.9.4, and versions 7.0.0 to 7.0.1. According to official public data, more than 400 million websites were previously running these affected versions, although this number does not completely exclude sites that have recently been patched.

Cybersecurity consultant Daniel Card surveyed a sample of about 3,500WordPressWebsite Post estimates that less than 15% of websites are currently vulnerable. If this ratio is extrapolated to the entire InternetWordPressBased on the website base, the total number of threatened sites is still as high as approximately 90 million.

Industry experts also expressed recognition of the active defense of many parties. Among them, security researchers praisedWordPressAdvancing initiatives for automatic updates, notingCloudflare blocks malicious attacks targeting vulnerable websites, and at the same time, many websites rely on security protection measures such as web firewalls to control the number of sites actually hacked by hackers within a certain range.

WordPress.orgThe developer did not immediately comment. However, responsible for operatingWordPress.comMegan Fox, a spokesperson for Automattic, the parent company that contributed to the open source project, said that all sites hosted by Automattic were protected before the vulnerability fix was released, and they were deployed to millions of websites immediately after the code update was released.

One of the keyThe WordPress vulnerability was discovered and reported by Adam Kues, a researcher at cybersecurity firm Searchlight Cyber, the vulnerability was named WP2Shell. When combined with another vulnerability, the hacker was able to achieve complete remote control of the vulnerable website.