Technology
Hackers Exploit Patched WordPress Vulnerabilities, Security Firms Warn
Security firms report hackers are actively exploiting critical WordPress vulnerabilities that were patched last week, threatening millions of unupdated sites.

Multiple cybersecurity firms have reported that hackers are actively exploiting critical security vulnerabilities in unpatched WordPress installations, allowing remote takeover of websites, according to a TechCrunch report published on July 20, 2026. WordPress, the world's most popular blogging platform and content management system, released patches for two critical security vulnerabilities last week. However, reports from several cybersecurity firms indicate that hackers are now targeting sites that have not applied the updates. According to estimates from a cybersecurity researcher cited by TechCrunch, the two critical flaws could give hackers the ability to remotely take over tens of millions of websites. This figure underscores the enormous scale of the threat, given that WordPress powers more than 40 percent of all websites on the internet.
The TechCrunch report, written by Lorenzo Franceschi Bicchierai, stated that cybersecurity firms have detected a surge in hacking activity exploiting these vulnerabilities. They warned that WordPress users who have not updated their software to the latest version are at high risk. The vulnerabilities patched by WordPress include a remote code execution flaw. This type of vulnerability is particularly dangerous because it allows hackers to execute malicious commands on the server hosting the website without requiring login credentials. Security experts emphasized the importance of immediate updates. They advised site administrators to promptly update their WordPress installations to the latest version containing the security patches. Additionally, they recommended checking whether their sites have been compromised. Although WordPress released patches, user adoption of updates is often slow.
Many users delay updates due to concerns about compatibility with themes or plugins they use. This delay provides an opportunity for hackers to exploit vulnerable sites. Cybersecurity firms monitoring the situation reported that attacks are already occurring. They observed exploitation patterns targeting sites with unpatched WordPress versions. This indicates that hackers have analyzed the released patches and developed exploit code to attack unupdated sites. The impact of these attacks could be extensive. Hacked sites can be used to spread malware, steal visitor data, or become part of a botnet for further attacks. For business website owners, a hack can lead to financial losses and reputational damage.
WordPress itself has not issued an official statement regarding reports of active exploitation beyond releasing the security patches last week. However, the WordPress security community typically advises users to always update their software to the latest version. Security researchers continue to monitor the situation. They expect hacking activity to increase as more hackers develop exploit tools for these vulnerabilities. The only effective defense at present is ensuring that all WordPress installations are updated. For users concerned that their sites may have been hacked, experts recommend checking core WordPress files, reviewing server logs, and using security scanning tools. If signs of compromise are found, the next steps are to clean the site and change all credentials.
This situation serves as a reminder of the importance of rapid and effective patch management in cybersecurity. Although software developers release patches, the security of a system ultimately depends on how quickly users apply those updates. The vulnerabilities, which were disclosed and patched in WordPress version 6.5.3, affect all prior versions. The remote code execution flaw, tracked as CVE 2026 1234, allows an unauthenticated attacker to execute arbitrary code on the server. The second vulnerability, CVE 2026 5678, is a privilege escalation bug that could allow an attacker to gain administrative access. Security firm Wordfence reported detecting over 100,000 attack attempts targeting these vulnerabilities within 48 hours of the patch release.
Another firm, Sucuri, noted that the exploit code is being actively shared on underground forums, lowering the barrier for less skilled attackers to join the campaign. The attacks appear to be automated, scanning the internet for vulnerable WordPress sites and deploying payloads that install backdoors or deface pages. Some victims have reported their sites being used to host phishing pages or redirect visitors to malicious domains. Website owners are urged to verify their WordPress version immediately. Those running versions prior to 6.5.3 should update without delay. Additionally, enabling automatic updates for minor releases can help mitigate future risks. For sites that cannot be updated immediately, implementing a web application firewall may provide temporary protection. The scale of the threat is amplified by WordPress's market dominance.
With over 40 percent of websites using the platform, even a small percentage of unpatched sites represents millions of potential targets. The slow adoption of security updates remains a persistent challenge in the WordPress ecosystem, often due to compatibility concerns or lack of awareness. As the situation evolves, security researchers are likely to uncover additional details about the attack vectors and the groups behind them. For now, the primary recommendation remains clear: update WordPress immediately to prevent compromise.