
wordpress bugs Hackers are already exploiting newly patched WordPress vulnerabilities, according to TechCrunch’s latest reporting, turning a just-fixed software issue into an immediate threat for website owners at a scale that could reach tens of millions of sites. The warning comes only days after WordPress rushed out emergency fixes and urged administrators to update “immediately,” underscoring how quickly attackers can weaponize a bug once a public patch exists. ([techcrunch.com](https://techcrunch.com/2026/07/20/hackers-are-exploiting-recently-patched-wordpress-bugs-putting-millions-of-websites-at-risk/))
wordpress bugs
Critical bugs patched, then quickly targeted
On July 20, 2026, TechCrunch reported that several cybersecurity firms were seeing active exploitation of recently patched WordPress flaws. WordPress had fixed two critical security vulnerabilities the week before and, because of the severity, enabled forced updates where possible. Even with those measures, researchers at Patchstack, Hexastrike and WatchTowr said attackers were already using the bugs in the wild to take over websites that had not yet been updated. ([techcrunch.com](https://techcrunch.com/2026/07/20/hackers-are-exploiting-recently-patched-wordpress-bugs-putting-millions-of-websites-at-risk/))
The article did not describe the flaws as isolated or theoretical. Instead, it framed them as live internet-facing risks affecting the world’s most widely deployed content management system. That matters because WordPress is not a niche platform: TechCrunch said vulnerable versions include 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1, and that WordPress’ own statistics suggest more than 400 million websites were still running those versions at the time of reporting, although many of those sites may already have been patched. ([techcrunch.com](https://techcrunch.com/2026/07/20/hackers-are-exploiting-recently-patched-wordpress-bugs-putting-millions-of-websites-at-risk/))
The scale could still be enormous
One of the most striking details in TechCrunch’s report is the size of the possible exposure. The publication cited one estimate that put the number of vulnerable WordPress websites at “tens of millions” as of Monday, July 21, 2026. Cybersecurity consultant Daniel Card offered a more specific way to think about the problem: after examining a sample of roughly 3,500 WordPress sites, he estimated that fewer than 15% were still vulnerable. Applied broadly, that would still leave around 90 million websites exposed, according to the article. ([techcrunch.com](https://techcrunch.com/2026/07/20/hackers-are-exploiting-recently-patched-wordpress-bugs-putting-millions-of-websites-at-risk/))
Those numbers should be treated carefully, but even the lower-end estimate is severe. WordPress is used across personal blogs, business sites, publisher pages, ecommerce storefronts, and nonprofit properties, so the blast radius of a flaw in its core software is unusually wide. TechCrunch noted that automatic updates and site-level defenses such as web application firewalls help reduce the number of systems attackers can successfully compromise, but those protections are not universal. ([techcrunch.com](https://techcrunch.com/2026/07/20/hackers-are-exploiting-recently-patched-wordpress-bugs-putting-millions-of-websites-at-risk/))
How the exploitation works
According to TechCrunch, the two flaws work together in a way that can give an attacker full remote control over a vulnerable website. One of the bugs was identified and reported by Adam Kues of Searchlight Cyber, which dubbed it WP2Shell. Paired with the second bug, the issue can allow hackers to seize control of affected sites. ([techcrunch.com](https://techcrunch.com/2026/07/20/hackers-are-exploiting-recently-patched-wordpress-bugs-putting-millions-of-websites-at-risk/))
The reporting does not suggest a sophisticated one-off intrusion against a single target. Instead, it points to broad abuse of a widely available weakness. That is consistent with the pattern seen in many web platform attacks: once exploit details circulate and patches are public, opportunistic attackers move quickly against unpatched servers and plugins. In this case, the speed of exploitation is especially concerning because WordPress itself pushed updates urgently, signaling that the issue was serious enough to justify immediate remediation. ([techcrunch.com](https://techcrunch.com/2026/07/20/hackers-are-exploiting-recently-patched-wordpress-bugs-putting-millions-of-websites-at-risk/))
Why so many sites remain exposed
There are several reasons WordPress bugs like these remain a recurring problem. First, the platform’s footprint is massive, and site owners vary widely in technical skill. Some update immediately; others delay maintenance, rely on hosting providers, or simply do not realize their site is outdated. Second, WordPress ecosystems often include third-party hosting and layered security products, which can make patching uneven. Third, even when core software is updated quickly, not every site owner notices or verifies the change. ([techcrunch.com](https://techcrunch.com/2026/07/20/hackers-are-exploiting-recently-patched-wordpress-bugs-putting-millions-of-websites-at-risk/))
TechCrunch also reported that Automattic, the company behind WordPress.com and a contributor to the open source project, said its hosted services were protected before the release and that it deployed the updates immediately across millions of sites once the code patches were published. That helps explain why managed platforms can be safer than self-hosted ones: they can patch centrally, rather than waiting for each individual administrator to act. ([techcrunch.com](https://techcrunch.com/2026/07/20/hackers-are-exploiting-recently-patched-wordpress-bugs-putting-millions-of-websites-at-risk/))
What administrators should take away
The immediate lesson is straightforward: patching is not optional. The article shows that waiting even a short time after a security release can leave websites open to exploitation. For WordPress administrators, that means checking the core version, confirming automatic updates are enabled where appropriate, and reviewing whether any plugins or hosting layers introduce additional exposure. TechCrunch’s reporting also points to a broader reality: where core vulnerabilities are actively exploited, defenses like firewalls and managed hosting can buy time, but only actual updates close the door. ([techcrunch.com](https://techcrunch.com/2026/07/20/hackers-are-exploiting-recently-patched-wordpress-bugs-putting-millions-of-websites-at-risk/))
There is also a reputational risk for site owners. A compromise of a WordPress site can lead to defacement, credential theft, malware distribution, or the use of the site as a launchpad for further attacks. Even if a vulnerable site has not yet been touched, the existence of active exploitation means attackers are already scanning for it. In practical terms, that turns patch management into an urgent operational task, not a background maintenance item. ([techcrunch.com](https://techcrunch.com/2026/07/20/hackers-are-exploiting-recently-patched-wordpress-bugs-putting-millions-of-websites-at-risk/))
A familiar security pattern, but on a very large stage
WordPress security incidents are hardly new, but this report is another reminder that the most dangerous bugs are often the ones that become public just as they are fixed. Once a patch is available, defenders can protect themselves, but so can attackers reverse-engineer the vulnerability and start looking for lagging sites. The result is a race between patch adoption and exploitation — and with a platform as large as WordPress, the race can involve millions of websites at once. ([techcrunch.com](https://techcrunch.com/2026/07/20/hackers-are-exploiting-recently-patched-wordpress-bugs-putting-millions-of-websites-at-risk/))
For the broader internet, the story is less about a single bug than about the speed of the response chain. WordPress moved quickly, researchers quickly documented exploitation, and the remaining risk now sits with the huge population of sites that still have not updated. If TechCrunch’s estimate is even directionally correct, the number of exposed websites is large enough to keep attackers busy for some time. ([techcrunch.com](https://techcrunch.com/2026/07/20/hackers-are-exploiting-recently-patched-wordpress-bugs-putting-millions-of-websites-at-risk/))
Explore more: Blog Our Services Contact Us
Source: Original report
Was this helpful?
Last Modified: July 21, 2026 at 6:38 pm
2 views

