WordPress Flaws Under Active Exploitation Threaten Tens of Millions of Sites
A two‑bug chain grants unauthenticated remote code execution, and widespread scanning plus public exploit code make immediate patching and forensic checks urgent.
Overview
- Security researchers disclosed two chained WordPress vulnerabilities that let attackers run code without logging in, and WordPress issued emergency fixes plus forced automatic updates to stop further abuse.
- Proof‑of‑concept exploit code appeared within hours of disclosure and security firms report dozens of exploit variants and large‑scale scanning targeting unpatched sites.
- Because WordPress runs a large share of the web, even a small vulnerable fraction could mean tens of millions of at‑risk sites, so defenders should not assume automatic updates reached every installation.
- Observed attacker activity includes mass spraying, creation of backdoor administrator accounts, fake plugin deployment, and attempts to fetch malware such as the Overlord RAT to enable site takeover and data theft.
- Site owners should update immediately to the patched releases, inspect for new admin users and malicious files, and use web application firewalls or services like Cloudflare to reduce ongoing attack risk.