If you run a WordPress site, this is your reminder to update it. Right now. Researchers have confirmed hackers are actively exploiting two vulnerabilities that got patched last week, meaning any site still on the old version is basically sitting with the door open.

The Attacks Are Already Happening

WordPress rolled out patches last week, but security firms Patchstack, WatchTowr, and Hexastrike are all reporting the same thing: attackers aren’t waiting around. These aren’t theoretical risks anymore; they’re being used right now to break into sites that haven’t updated yet.

Millions of Sites Still at Risk

The affected versions are WordPress 6.9.0 through 6.9.4, and 7.0.0 through 7.0.1. WordPress pushed automatic updates where it could, but experts think millions of sites are still running the vulnerable versions. Automatic updates and firewalls have helped, sure, but a lot of sites are still exposed.

What’s Actually Kept the Damage Down

A few things have limited how bad this could’ve been:

  • WordPress’s automatic security updates
  • Cloudflare’s attack mitigation
  • Firewalls and security plugins
  • Fast responses from managed hosting providers

Sites relying on manual updates, or running with no extra protection, are the ones still in real danger.

One Exploit Chain Can Hand Over Full Control

One of the flaws, nicknamed WP2Shell, gets seriously dangerous when paired with another vulnerability. Combined, they let attackers remotely run code and potentially take complete control of a site. From there, they can mess with content, steal data, drop malware, or use the site as a launchpad for bigger attacks elsewhere.

What You Should Do Right Now

  • Update WordPress to the latest patched version
  • Check admin accounts for anything unfamiliar
  • Go through server logs and website files for suspicious activity
  • Make sure your firewall and security plugins are active and current
  • Keep regular backups going

Updating fast is still the single best defense here.

FAQs

1. Which WordPress versions are affected?
6.9.0–6.9.4 and 7.0.0–7.0.1. Update immediately if you’re on either.

2. What’s WP2Shell?
One of the two flaws, when combined with the other, can let attackers take over a site remotely.

3. Does automatic updating mean I’m safe?
Probably already patched, but it’s worth double-checking the update actually went through.

4. How do I know if I’ve already been hit?
Check admin accounts, scan server logs, look for unauthorized file changes, and watch for security alerts.

Bottom Line

These WordPress flaws went from patched to actively exploited fast, proof of how quickly delays turn costly. Automatic updates and security tools have blunted the impact, but outdated sites are still very much in the crosshairs. Updating promptly, watching for anything odd, and keeping backups is really the whole game plan here.