Search Beyond News…

Critical WordPress zero‑day flaws expose tens of millions of sites to remote takeover

Executive summary: Two critical security flaws in WordPress’ core code were exploited by hackers, enabling remote takeover of tens of millions of websites, according to a cybersecurity researcher’s estimate. WordPress powers over 40 % of all websites, so the vulnerabilities threaten a large share of the web, potentially leading to data breaches, defacement, and service disruption across businesses and individuals.

Who is involved: WordPress core developers, the undisclosed cybersecurity researcher who identified the exploit, hosting providers, and website administrators.

Likely next: WordPress is expected to release an emergency security patch within days, while hosting providers and site owners will scan for compromised instances and apply updates.

On July 20 2026, TechCrunch reported that two newly disclosed critical vulnerabilities in WordPress core software allow attackers to execute remote code and seize control of websites at scale. A cybersecurity researcher estimated that the flaws could affect tens of millions of installations, given WordPress’s market share exceeding 40 % of all sites. The disclosure follows a recent patch cycle, highlighting the lag between fix release and adversary exploitation. Immediate actions by hosting providers and site administrators are needed to mitigate the risk.

Timeline

Analysis — what this means

Sectors affected

Regulatory implications

Historical parallels

Key entities

Sources

Browse the full archive →