{"id":3453,"date":"2026-07-21T11:58:11","date_gmt":"2026-07-21T11:58:11","guid":{"rendered":"https:\/\/justfineinfotech.com\/hackers-are-exploiting-recently-patched-wordpress-bugs-putting-millions-of-websites-at-risk-techcrunch\/"},"modified":"2026-07-21T11:58:11","modified_gmt":"2026-07-21T11:58:11","slug":"hackers-are-exploiting-recently-patched-wordpress-bugs-putting-millions-of-websites-at-risk-techcrunch","status":"publish","type":"post","link":"https:\/\/justfineinfotech.com\/fr\/hackers-are-exploiting-recently-patched-wordpress-bugs-putting-millions-of-websites-at-risk-techcrunch\/","title":{"rendered":"Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk | TechCrunch"},"content":{"rendered":"<p>Hackers are breaking into websites that run vulnerable versions of the popular blogging software WordPress, according to several cybersecurity firms. One estimate puts the number of vulnerable WordPress websites at tens of millions as of Monday<\/p>\n<p>Last week, <a href=\"https:\/\/wordpress.org\/news\/2026\/07\/wordpress-7-0-2-release\/\" rel=\"nofollow noopener\" target=\"_blank\">WordPress patched two critical security flaws<\/a>, urging people who run its software on their websites to update it \u201cimmediately.\u201d The vulnerabilities are so severe that WordPress enabled forced updates where possible. Since then, cybersecurity companies Patchstack, Hexastrike, and WatchTowr <a href=\"https:\/\/www.securityweek.com\/wp2shell-wordpress-vulnerabilities-exploited-in-the-wild\/#:~:text=WP2Shell%20exploited%20in%20the%20wild\" rel=\"nofollow noopener\" target=\"_blank\">have all warned<\/a> that hackers are exploiting the vulnerabilities in the wild, meaning they are taking over websites that are still running susceptible versions of WordPress.\u00a0<\/p>\n<p>It\u2019s unclear how many WordPress-powered websites on the internet are at risk, but it\u2019s possible to make some educated guesses. The vulnerable versions of WordPress are 6.9.0 through 6.9.4, and 7.0.0 to 7.0.1. According to WordPress\u2019 official stats, there are more than 400 million websites that run those flawed versions, although these statistics likely don\u2019t reflect websites that have recently been patched.<\/p>\n<p>Cybersecurity consultant Daniel Card, who told <a href=\"https:\/\/justfineinfotech.com\/fr\/natural-raises-30m-to-reinvent-payments-for-ai-agents-and-take-on-stripe-techcrunch\/\" title=\"Natural raises $30M to reinvent payments for AI agents \u2014 and take on Stripe | TechCrunch\">TechCrunch<\/a> that he looked at a sample of around 3,500 WordPress websites, estimates that less than 15%are vulnerable. Applying Card\u2019s projection across the total population of WordPress websites on the internet, the total figure would still be around 90 million<\/p>\n<p>The researcher credited WordPress with pushing automatic updates, Cloudflare with <a href=\"https:\/\/blog.cloudflare.com\/wordpress-vulnerabilities\/\" rel=\"nofollow noopener\" target=\"_blank\">blocking attacks<\/a> against vulnerable websites, and websites using cybersecurity protections such as web firewalls for the limited number of sites that could currently be hacked.\u00a0<\/p>\n<p>WordPress.org, the project that develops WordPress\u2019 open source code, did not immediately respond to a request for comment.\u00a0Megan Fox, a spokesperson for Automattic, the company that runs WordPress.com and contributes to the open source project, told TechCrunch that \u201call sites hosted by Automattic, including <a href=\"http:\/\/WordPress.com\" rel=\"nofollow noopener\" target=\"_blank\">WordPress.com<\/a>, Pressable, WPVIP, and WP.cloud partners, were protected even before the release. When the code updates were published, we deployed them immediately across millions of sites.\u201d<\/p>\n<p>One of the critical WordPress bugs was found and reported by Adam Kues of cybersecurity firm Searchlight Cyber, which dubbed it WP2Shell. Paired with the other bug, hackers can take full remote control of vulnerable websites<\/p>\n<div style=\"clear:both;margin:30px 0 15px 0\">\n<p>\n    <strong>En rapport:<\/strong><br \/>\n    <a href=\"https:\/\/yoursite.com\/automation-training-benin\/\" title=\"Formation en automatisation num\u00e9rique au B\u00e9nin\u00a0: 5 comp\u00e9tences cl\u00e9s recherch\u00e9es par les employeurs en 2026\" target=\"_blank\" rel=\"noopener\"><br \/>\n      Formation en automatisation num\u00e9rique au B\u00e9nin\u00a0: 5 comp\u00e9tences cl\u00e9s recherch\u00e9es par les employeurs en 2026<br \/>\n    <\/a>\n  <\/p>\n<p>\n    &lt;a href=&quot;https:\/\/yoursite.com\/automation-africa\/&quot; title=&quot;<a href=\"https:\/\/justfineinfotech.com\/fr\/meta-wants-to-charge-for-social-impact-whatsapp-messages-ictworks\/\" title=\"Meta souhaite faire payer les messages WhatsApp \u00e0 impact social - ICTworks\">WhatsApp<\/a> Automatisation du marketing en Afrique : 6 <a href=\"https:\/\/justfineinfotech.com\/fr\/how-st-therese-can-help-with-a-big-work-from-home-danger\/\" title=\"Comment Sainte Th\u00e9r\u00e8se peut aider face \u00e0 un grand danger li\u00e9 au t\u00e9l\u00e9travail\">Danger<\/a>Les erreurs que font les marques au Nig\u00e9ria\u201d&gt;<br \/>\n      Automatisation du marketing WhatsApp en Afrique\u00a0: 6 erreurs dangereuses commises par les marques au Nig\u00e9ria<br \/>\n    <\/a>\n  <\/p>\n<\/div>\n<div style=\"clear:both;margin:30px 0;padding:25px;background:#f8f9fc;border:1px solid #ddd;border-radius:8px;text-align:center\">\n<h3>Vous souhaitez apprendre cela de mani\u00e8re pratique ?<\/h3>\n<p>Rejoindre <strong>Justfine Infotech<\/strong> et d\u00e9velopper de v\u00e9ritables comp\u00e9tences num\u00e9riques en IA, automatisation, d\u00e9veloppement web, marketing digital, bureautique, e-commerce, travail ind\u00e9pendant et cybers\u00e9curit\u00e9.<\/p>\n<p><strong>Programmes disponibles :<\/strong><br \/>\n  Certificat de 6 semaines \u2022 Certificat professionnel de 3 mois \u2022 Dipl\u00f4me de 6 mois \u2022 Dipl\u00f4me professionnel complet<\/p>\n<p><strong>WhatsApp :<\/strong><br \/>\n  +229 01 57 57 99 15<br \/>\n  +229 01 66 68 11 60<\/p>\n<p><a href=\"https:\/\/api.whatsapp.com\/send?phone=2348132690270&amp;text=Hello\" target=\"_blank\" rel=\"noopener\">Inscrivez-vous d\u00e8s maintenant<\/a><\/p>\n<\/div>\n<p class=\"ani-source\">Source: <a href=\"https:\/\/techcrunch.com\/2026\/07\/20\/hackers-are-exploiting-recently-patched-wordpress-bugs-putting-millions-of-websites-at-risk\/\" target=\"_blank\" rel=\"nofollow noopener\">techcrunch.com<\/a><\/p>","protected":false},"excerpt":{"rendered":"<p>Hackers are breaking into websites that run vulnerable versions of the popular blogging software WordPress, according to several cybersecurity firms. One estimate puts the number of vulnerable WordPress websites at tens of millions as of Monday<\/p>","protected":false},"author":1,"featured_media":3455,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[71],"tags":[711,710,713,712,188],"class_list":["post-3453","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity-online-scam-alerts","tag-exploiting","tag-hackers","tag-patched","tag-recently","tag-wordpress"],"_links":{"self":[{"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/posts\/3453","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/comments?post=3453"}],"version-history":[{"count":1,"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/posts\/3453\/revisions"}],"predecessor-version":[{"id":3454,"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/posts\/3453\/revisions\/3454"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/media\/3455"}],"wp:attachment":[{"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/media?parent=3453"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/categories?post=3453"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/justfineinfotech.com\/fr\/wp-json\/wp\/v2\/tags?post=3453"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}