Key Takeaways
- Patchstack, Hexastrike, and WatchTowr report active exploitation of newly patched WordPress core flaws
- Vulnerable versions may still number around 90 million sites, based on a cybersecurity consultant’s sampling
- Rapid exploit cycles mirror wider industry trends flagged by Gartner, Forrester, and IEEE on accelerating vulnerability weaponization
Hackers moved quickly after WordPress issued fixes for two critical security flaws last week, and several security firms say the exploitation window proved incredibly short. Patchstack, Hexastrike, and WatchTowr all observed active attacks targeting websites that had not yet applied the new updates. It is a familiar pattern for many security teams, although the scale is worth pausing on.
The vulnerable WordPress versions span 6.9.0 through 6.9.4, plus 7.0.0 to 7.0.1. WordPress’ public usage data shows more than 400 million websites running those builds as of Monday. Even if many sites have already been updated, that denominator paints an enormous potential attack surface. A cybersecurity consultant analyzing a sample of around 3,500 sites reported that less than 15% remained vulnerable. Applied across the larger population, though, this still represents roughly 90 million websites that could be compromised.
One of the two critical bugs, reported by a researcher at Searchlight Cyber, has been labeled WP2Shell. When chained with the other flaw, an attacker can seize complete remote control of the target site. WordPress pushed automatic updates where it could, and in some environments forced updates were enabled. That said, not all operators run with automatic updates on, and some organizations still test core updates manually before deployment. These patterns tend to slow things down.
Security researchers have been pointing to this tightening patch-to-exploit gap for several years. Reporting from Patchstack in its 2026 State of WordPress Security analysis notes that in 2025 there were 11,334 new WordPress vulnerabilities. That represented a 42% year-over-year jump. The majority, 91%, occurred in plugins rather than WordPress core. This matters because plugin diversity creates unpredictable attack paths, which can complicate enterprise patch management.
The same report found 1,966 of those vulnerabilities were high severity, and attackers often began probing for them within a median of 5 hours after public disclosure. That aligns almost too well with what Hexastrike and WatchTowr saw this week. The phenomenon is broader than WordPress alone. Analysts at Gartner have repeatedly warned that vulnerability exploitation remains one of the leading initial access vectors across major breach investigations. Their advice often centers on tightening patch pipelines and expanding monitoring for early indicators of compromise.
ENISA’s 2024 Threat Landscape calls out vulnerability exploitation as one of the most persistent attack techniques in real-world incidents. That report is widely cited by CISOs because it frames the problem as a resource challenge as much as a technical one. Many teams simply cannot patch as quickly as attackers adapt. And WordPress is not a niche platform, so it often becomes a laboratory for observing threat actor behavior at scale.
The June 2026 plugin incidents highlighted by Adyog, which reported six actively exploited plugin flaws including the Kirki Customizer Framework affecting 500,000 installs, underline how common this situation has become. Those plugin issues differ technically from this new core problem, yet from an operations perspective they form a continuous stream of urgent fixes.
While industry analysts sometimes disagree on the best long-term model for securing large open source ecosystems, Forrester researchers have emphasized the importance of layered mitigation. They tend to highlight controls that reduce the blast radius when a vulnerability is exploited, such as segmentation or hardened defaults. For organizations running WordPress in revenue-facing environments, these types of controls can make the difference between a localized incident and a complete outage.
There is also the role of third parties such as Cloudflare. The initial cybersecurity sampling credited Cloudflare with blocking some of the exploit activity automatically. Many enterprises rely on web application firewalls to buy time during patch rollouts, and this event illustrates why. IEEE's security working groups, which often focus on internet-scale attack propagation, have argued that hybrid controls like these can slow down opportunistic attackers. Their publications frequently explore how rapid scanning tools and botnets search for unpatched installations within hours of vulnerability disclosure.
Automattic’s response provides another angle. A spokesperson for the company said all sites hosted across Automattic’s platforms, including WordPress.com, Pressable, WPVIP, and WP.cloud partners, were protected ahead of the public release and updated immediately once the patches landed. Enterprise leaders often ask whether managed hosting offers noticeable resilience improvements. This example at least shows how coordinated deployment across millions of sites can narrow the vulnerability window significantly.
Some observers might wonder whether an ecosystem this large can ever fully avoid these periodic waves of exploitation. Others point out that although WordPress core issues grab the headlines, industry research indicates plugins remain the dominant risk. Both points are true in their own way. The mix of centralized patching for core code and highly distributed maintenance for plugins creates an uneven risk profile that business leaders need to understand.
CISA’s Known Exploited Vulnerabilities Catalog continues to be one of the more trusted references for determining which CVEs demand immediate action. When vulnerabilities like WP2Shell appear, defenders often look to that catalog to prioritize internal workflows. It is a reminder that even in a highly automated environment, human triage still matters.
This week’s events illustrate a pattern that is not going away. Attackers track WordPress updates closely, and they act quickly when new opportunities arise. For enterprises that rely on WordPress for customer engagement, ecommerce, or content distribution, the operational lesson is familiar but pressing: shorten patch cycles where possible, monitor plugin risk continuously, and treat each disclosure as if exploitation will follow within hours.
⬇️