Critical WordPress zero‑day flaws expose tens of millions of sites to remote takeover
Executive summary: Two critical security flaws in WordPress’ core code were exploited by hackers, enabling remote takeover of tens of millions of websites, according to a cybersecurity researcher’s estimate. WordPress powers over 40 % of all websites, so the vulnerabilities threaten a large share of the web, potentially leading to data breaches, defacement, and service disruption across businesses and individuals.
Who is involved: WordPress core developers, the undisclosed cybersecurity researcher who identified the exploit, hosting providers, and website administrators.
Likely next: WordPress is expected to release an emergency security patch within days, while hosting providers and site owners will scan for compromised instances and apply updates.
On July 20 2026, TechCrunch reported that two newly disclosed critical vulnerabilities in WordPress core software allow attackers to execute remote code and seize control of websites at scale. A cybersecurity researcher estimated that the flaws could affect tens of millions of installations, given WordPress’s market share exceeding 40 % of all sites. The disclosure follows a recent patch cycle, highlighting the lag between fix release and adversary exploitation. Immediate actions by hosting providers and site administrators are needed to mitigate the risk.
Timeline
- — Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk (TechCrunch)
Analysis — what this means
Sectors affected
- Website hosting and managed services
- Cybersecurity threat intelligence firms
- WordPress plugin and theme developers
Regulatory implications
- EU Cybersecurity Act may trigger mandatory breach reporting for affected entities
- US CISA could issue an emergency directive urging federal agencies to patch WordPress instances
- Potential fines under GDPR if personal data is exposed via compromised WordPress sites
Historical parallels
- WordPress 4.7.0 REST API vulnerability (March 2017) that allowed unauthenticated content injection
- Equifax data breach (July‑September 2017) exploiting an unpatched Apache Struts flaw
- WannaCry ransomware attack (May 2017) leveraging the EternalBlue SMB vulnerability