Schedule a Cybersecurity Lunch and Learn with Your Staff
Register Now!
Download our Cybersecurity Health Checkup Document
Download Now!
Download our Small Business IT Buyers Guide
Download Now!
Download our Cybersecurity Essentials For Business Owners
Download Now!

Critical WordPress Vulnerability Under Active Attack: What Site Owners Need to Know

Critical WordPress Vulnerability Under Active Attack: What Site Owners Need to Know

A critical security flaw has been disclosed in WordPress core, the software that powers roughly 40 percent of all websites. Attackers are already exploiting it in the wild, and it is serious: the vulnerability allows unauthenticated remote code execution. In plain terms, an attacker can take control of a vulnerable site without ever needing a password.

Which versions are affected

The flaw affects WordPress core versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. Any site running one of these versions should be treated as at risk until it is updated. The fixed releases are 6.9.5 and later on the 6.9 branch, and 7.0.2 and later on the 7.0 branch.

What the attacks look like

We are seeing automated bots scan for and compromise vulnerable sites at scale. Once inside, the typical pattern includes:

  • Hidden backdoors planted throughout the site so the attacker can return at will
  • Fake administrator accounts created to preserve access
  • SEO spam and doorway pages injected to hijack search rankings
  • Reinfection within days if the underlying vulnerability is not patched

That last point is the one most site owners miss. Cleaning up the visible symptoms is not enough on its own. If the door that let the attacker in is still open, they simply walk back through it.

What to do right now

  1. Update WordPress core to 6.9.5 or newer, or 7.0.2 or newer, immediately.
  2. Turn on automatic background updates so future security patches apply themselves.
  3. Put your administrator login behind a second layer, such as HTTP authentication or an IP allow-list, to blunt automated attacks.
  4. If your site runs an old or unsupported version of WordPress, treat the upgrade as urgent.

How we protect the sites we manage

Every site we host has already been updated to a patched version. Beyond that single fix, we have enabled automatic security updates across every site we manage, placed all WordPress administrator logins behind an authentication gate, and added off-server logging and monitoring so that an intruder cannot quietly erase their tracks. We treat security as a continuous, proactive discipline rather than a one-time cleanup after something has already gone wrong.

Staying patched, staying monitored, and closing the door before it is used is the difference between a quiet non-event and a costly compromise.

Facebook
Twitter
LinkedIn