Hackers Are Already Exploiting Unpatched WordPress Sites
July 24, 2026
If you run a WordPress site, this is your reminder to update it. Right now. Researchers have confirmed hackers are actively exploiting two vulnerabilities that got patched last week, meaning any site still on the old version is basically sitting with the door open.
The Attacks Are Already Happening
WordPress rolled out patches last week, but security firms Patchstack, WatchTowr, and Hexastrike are all reporting the same thing: attackers aren’t waiting around. These aren’t theoretical risks anymore; they’re being used right now to break into sites that haven’t updated yet.
Millions of Sites Still at Risk
The affected versions are WordPress 6.9.0 through 6.9.4, and 7.0.0 through 7.0.1. WordPress pushed automatic updates where it could, but experts think millions of sites are still running the vulnerable versions. Automatic updates and firewalls have helped, sure, but a lot of sites are still exposed.
What’s Actually Kept the Damage Down
A few things have limited how bad this could’ve been:
- WordPress’s automatic security updates
- Cloudflare’s attack mitigation
- Firewalls and security plugins
- Fast responses from managed hosting providers
Sites relying on manual updates, or running with no extra protection, are the ones still in real danger.
One Exploit Chain Can Hand Over Full Control
One of the flaws, nicknamed WP2Shell, gets seriously dangerous when paired with another vulnerability. Combined, they let attackers remotely run code and potentially take complete control of a site. From there, they can mess with content, steal data, drop malware, or use the site as a launchpad for bigger attacks elsewhere.
What You Should Do Right Now
- Update WordPress to the latest patched version
- Check admin accounts for anything unfamiliar
- Go through server logs and website files for suspicious activity
- Make sure your firewall and security plugins are active and current
- Keep regular backups going
Updating fast is still the single best defense here.
FAQs
1. Which WordPress versions are affected?
6.9.0–6.9.4 and 7.0.0–7.0.1. Update immediately if you’re on either.
2. What’s WP2Shell?
One of the two flaws, when combined with the other, can let attackers take over a site remotely.
3. Does automatic updating mean I’m safe?
Probably already patched, but it’s worth double-checking the update actually went through.
4. How do I know if I’ve already been hit?
Check admin accounts, scan server logs, look for unauthorized file changes, and watch for security alerts.
Bottom Line
These WordPress flaws went from patched to actively exploited fast, proof of how quickly delays turn costly. Automatic updates and security tools have blunted the impact, but outdated sites are still very much in the crosshairs. Updating promptly, watching for anything odd, and keeping backups is really the whole game plan here.




