
There are tens of millions of WordPress sites; there’s a good chance you or your company has one or more. Hackers are actively exploiting two vulnerabilities in WordPress core. Used together, the flaws can let an unauthenticated attacker take full control of a website. WordPress released emergency fixes on July 17, but Patchstack says it is observing attacks on sites that have not been updated.
The affected versions are easy to identify. WordPress 6.9 through 7.0.1 contain both vulnerabilities. WordPress 6.8 contains the SQL injection flaw. Versions earlier than 6.8 are unaffected by these two specific bugs, although running an old WordPress release creates other security problems.
Log in to your WordPress admin panel and open Dashboard > Updates. You should be running WordPress 7.0.2, 6.9.5, or 6.8.6, depending on your release branch. WordPress has enabled forced automatic updates because of the severity, but automatic updates can fail or be disabled by a hosting configuration. Confirm the installed version yourself, or ask your hosting provider to confirm it in writing.
If your site is still running an affected version, back up its database and files, then install the available security update immediately. After updating, review the administrator list for accounts you do not recognize and ask your security or hosting team to examine access logs and site files for signs of compromise. A successful update closes the vulnerabilities; it does not remove an attacker who may already have gained access.
WordPress powers an enormous share of the web. Please pass this along to whoever maintains your company website.
P.S. The official WordPress security notice lists the affected releases and fixed versions.




Comments
Log in or sign up to join the conversation.