Two critical WordPress flaws leave millions of websites open to takeover.

Two critical WordPress security flaws now give hackers a remote path into tens of millions of websites, according to a cybersecurity researcher's estimate.

3 min readTechCrunch
Two critical WordPress flaws leave millions of websites open to takeover.

Two critical security flaws in WordPress software have given hackers a remote path to take over tens of millions of websites, according to a cybersecurity researcher's estimate. That is not a hypothetical risk or a vague warning. It is a concrete, active threat facing anyone who runs a site on the world's most popular content management system. If you manage a WordPress site, this is the moment to stop treating updates as optional housekeeping and start treating them as the primary defense they are. The patches exist. The question is whether enough site owners will apply them before the attackers do.

This story is not really about the flaws themselves, though the technical details matter. It is about the gap between knowing and doing. Most WordPress users are not developers or security professionals. They are small business owners, bloggers, and nonprofit coordinators who chose WordPress because it was accessible and flexible. That accessibility has a cost: it makes the platform a massive target. When a researcher estimates that tens of millions of sites are exposed, that number is not abstract. It is your portfolio site, your client's online store, your local newspaper's comment section. The practical takeaway here is blunt: if you have not updated WordPress in the last week, you are not just behind. You are exposed. The fix is not complicated, but it is urgent. Enable automatic updates if you can. Check your admin dashboard today. Make a habit of it.

For our readers who are wondering what to do next, we would say this: do not panic, but do move with purpose. The cybersecurity researcher's estimate is a signal, not a scare tactic. It tells us that attackers are actively scanning for unpatched sites, and they are not waiting for a convenient time. The good news is that WordPress's core team has already released fixes. The bad news is that a patch only helps if it is installed. That means you need to verify your site's version, confirm whether automatic updates are active, and then check again in a week. It is not glamorous work, but it is the kind of discipline that keeps a site alive. We would also suggest reviewing your hosting provider's security practices, since some managed hosts apply critical updates for you. But do not assume. Verify.

The open question this leaves us with is whether the broader WordPress ecosystem can shift its culture around security. Plugins and themes are frequent entry points, and even a well-maintained core can be undone by a neglected add-on. The researcher's estimate focuses on the core flaws, but the lesson extends further. Every site owner should ask themselves a simple question: if an attacker gained access tomorrow, what would they find? That is not a rhetorical prompt. It is a concrete checklist item. The specific detail to watch in the coming weeks is how quickly the patch adoption rate climbs, because that number will tell us whether the community is learning or repeating old mistakes. Do not wait for the next headline to act. The window between a patch and an exploit is measured in days, not months. Close it.

From TechCrunch

Two critical security flaws in WordPress’ software have given hackers the chance to remotely take over tens of millions of websites, according to an estimate by a cybersecurity researcher.

Read the original at TechCrunch