WordPress vulnerabilities are Urgent: If you own a WordPress Website, Update it Today!
Bottom line: this is one of those rare “drop what you’re doing” security issues. A few minutes checking your WordPress version today could save you from a costly, disruptive hack tomorrow.
Key takeaways:
Why These WordPress Vulnerabilities Matters to You Right Now
- Hackers can break into your site without a password. No login, no plugin flaw needed — a completely stock WordPress site can be taken over.
- Attacks are already happening. This isn’t a “someday” risk. Security firms confirmed real hackers are exploiting this right now, as you read this.
- Your site could be fully hijacked. Attackers who exploit this bug can take complete control — defacing your site, stealing customer data, or using it to attack others.
- The fix is fast, but only if you act. WordPress released a patch, but it only protects you once it’s installed on your site.
- Waiting even a few days is risky. Experts say the gap between “vulnerability announced” and “criminals actively using it” has shrunk from over a day to just hours.
What’s Going On (In Plain English)
Security researchers found two serious WordPress vulnerabilities (or flaws in WordPress), nicknamed “WP2Shell.” On their own, each one is bad. Combined, they let a hacker — with no account, no password, and no special access — remotely take over your website.
Researchers at Searchlight Cyber, the firm that discovered the problem, put it bluntly: this attack works against a brand-new, unmodified WordPress install with zero plugins. In other words, having a “simple” or “basic” site doesn’t protect you.
Which sites are affected? If your WordPress version falls into one of these ranges, you’re exposed:
- Versions 6.9.0 through 6.9.4
- Versions 7.0.0 through 7.0.1
The Good News: There’s Already a Fix
WordPress moved fast and released patched versions — 6.9.5 and 7.0.2 — that close the hole. Because the risk is so severe, WordPress.org even turned on automatic forced updates for many affected sites.
But “many” isn’t “all.” If your hosting provider doesn’t handle auto-updates, or if you’ve disabled them, your site is still sitting open right now.
Why Hackers Are Moving So Fast
This isn’t the usual slow-motion threat. According to WatchTowr founder Benjamin Harris, working exploit code showed up within hours of the vulnerability going public — a process that used to take a day or more. He put the stakes in simple terms: WordPress powers hundreds of millions of sites worldwide, and while some will get patched automatically by their host, plenty won’t — and that’s exactly where attackers will strike.
What You Should Do Today
- Check your WordPress version — log into your dashboard (Dashboard > Updates) and see what version you’re running. (See the image below).
- Update immediately if you’re on 6.9.0–6.9.4 or 7.0.0–7.0.1. Update to 6.9.5 or 7.0.2 or later.
- Don’t assume auto-update saved you. Confirm the update actually applied — check your version number again after updating.
- If you suspect you were already hacked (strange admin accounts, unfamiliar files, site behaving oddly), get a security professional to check for signs of compromise — don’t just apply the patch and hope for the best.
- If you have a web designer/developer, contact them today and ask them to confirm your site is patched.
Once your WordPress version is updated, you will see an image like the one below, indicating that you are now on version 7.0.2.
Given the critical nature of the recent unauthenticated Remote Code Execution flaw patching WordPress Core, leaving your site on an unpatched version puts your data, user trust, and business operations at immediate risk. Upgrading to WordPress 7.0.2 (or the corresponding patched release for your branch) is an urgent priority to secure your system against exploitation. If you need assistance verifying your update status, safely applying patches without breaking custom features, or auditing your site’s security posture, reach out to MCBI today—our team is ready to ensure your digital assets remain fully protected.