Millions of websites at risk: Attackers exploit bug in WordPress

Millions of websites are currently at risk of a successful attack. An error became known in WordPress, the world’s most popular content management system, and the first exploits quickly began circulating.
Auto-updates help somewhat
Basically all websites that run on WordPress and have not yet been provided with the latest updates are affected by the problem. Last week, the WordPress developers closed two security gaps that were classified as critical and asked website operators to update their installations immediately. Due to the severity of the security problems, automatic updates were activated wherever this was technically possible, reports the US technology portal TechCrunch. Nevertheless, the security companies Patchstack, Hexastrike and WatchTowr report that the vulnerabilities are now being used specifically for attacks.
It is currently not possible to precisely quantify how many websites are actually still at risk. WordPress versions 6.9.0 to 6.9.4 as well as 7.0.0 and 7.0.1 are vulnerable. According to official statistics, these versions account for more than 400 million installations. It is not yet possible to say exactly how many of these have already been updated. Due to the forced automatic updates, IT security consultant Daniel Card comes to a significantly lower estimate of how many websites are actually threatened. After evaluating around 3,500 WordPress websites, he assumes that less than 15 percent are still vulnerable. Even on this basis, around 90 million websites worldwide could still be at risk.
Definitely update!
Card attributes the fact that the number is not even higher to several protective measures. In addition to the automatically distributed WordPress updates, Cloudflare’s protection mechanisms also help ward off attacks on vulnerable websites. Additionally, many operators benefit from web application firewalls and other security solutions that block known attack attempts. Automattic, the company behind WordPress.com and a key co-developer of the open source project, told TechCrunch that all Automattic-operated hosting plans were already secured before the updates were released. After the bug fixes were released, they were immediately applied to millions of hosted websites. If you run WordPress installations yourself, you should make sure that they are updated to version 7.0.2.