Millions of WordPress Sites at Risk

Here is a simple public service announcement. There are tens of millions of WordPress sites; there’s a good chance you or your company has one or more. Hackers are actively exploiting two vulnerabilities in WordPress core. Used together, the flaws can let an unauthenticated attacker take full control of a website. WordPress released emergency fixes on July 17, but Patchstack says it is observing attacks on sites that have not been updated.

The affected versions are easy to identify. WordPress 6.9 through 7.0.1 contain both vulnerabilities. WordPress 6.8 contains the SQL injection flaw. Versions earlier than 6.8 are unaffected by these two specific bugs, although running an old WordPress release creates other security problems.

Log in to your WordPress admin panel and open Dashboard > Updates. You should be running WordPress 7.0.2, 6.9.5, or 6.8.6, depending on your release branch. WordPress has enabled forced automatic updates because of the severity, but automatic updates can fail or be disabled by a hosting configuration. Confirm the installed version yourself, or ask your hosting provider to confirm it in writing.

If your site is still running an affected version, back up its database and files, then install the available security update immediately. After updating, review the administrator list for accounts you do not recognize and ask your security or hosting team to examine access logs and site files for signs of compromise. A successful update closes the vulnerabilities; it does not remove an attacker who may already have gained access.

WordPress powers an enormous share of the web. Please pass this along to whoever maintains your company website.

P.S. The ​​official WordPress security notice lists the affected releases and fixed versions.

Every company needs a Claw strategy. Do you have one?

Author’s note: This is not a sponsored post. I am the author of this article and it expresses my own opinions. I am not, nor is my company, receiving compensation for it. This work was created with the assistance of various generative AI models.

About Shelly Palmer

Shelly Palmer is the Professor of Advanced Media in Residence at Syracuse University’s S.I. Newhouse School of Public Communications and CEO of The Palmer Group, a consulting practice that helps Fortune 500 companies with technology, media and marketing. Named LinkedIn’s “Top Voice in Technology,” he covers tech and business for Good Day New York, is a regular commentator on CNN and writes a popular daily business blog. He's a bestselling author, and the creator of the popular, free online course, Generative AI for Execs. Follow @shellypalmer or visit shellypalmer.com.

Tags

Categories

PreviousBoris Cherny's Steps of AI Adoption: A Roadmap NextOpenAI Joins the Race for SMBs