Millions of WordPress websites across the world are facing a renewed cybersecurity threat after researchers discovered that hackers are actively exploiting vulnerabilities that have already been patched. Security experts warn that many website owners have delayed installing critical updates, leaving their sites exposed to attacks.
According to cybersecurity researchers, attackers are using a technique known as WP2Shell, which allows them to gain remote control of vulnerable websites. Once successful, hackers can upload malicious files, execute harmful code and potentially take complete control of affected servers.
The concern is not that WordPress itself has introduced new flaws, but that many websites continue to run outdated versions of WordPress plugins and themes. Although developers have already released security patches, a significant number of site owners have failed to install them, creating an opportunity for cybercriminals.
Security researchers say hackers are scanning the internet for websites that remain unpatched. Automated tools help attackers identify vulnerable installations within minutes, making even small business websites, blogs and personal websites potential targets.
The WP2Shell attack chain combines several known vulnerabilities that have already been fixed. By exploiting these weaknesses together, attackers can bypass normal website protections and achieve remote code execution, one of the most dangerous forms of cyberattack. This allows criminals to install malware, steal sensitive information, redirect visitors to malicious websites or use compromised servers for larger cybercrime operations.
Experts estimate that millions of websites could still be at risk because WordPress powers more than 40 percent of all websites worldwide. Its popularity makes it an attractive target for hackers, who often focus on outdated plugins rather than the WordPress core software.
Cybersecurity analysts stress that the responsibility now lies largely with website administrators. Installing updates promptly remains the most effective defence against these attacks. Delaying security patches, even for a few weeks, can leave websites vulnerable once attackers begin exploiting publicly disclosed flaws.
Researchers also recommend removing unused plugins and themes, as these can become easy entry points if they are no longer maintained. Website owners should download plugins only from trusted sources and avoid pirated or unofficial versions, which may already contain malicious code.
In addition to regular updates, experts advise enabling multi-factor authentication, using strong administrator passwords and maintaining frequent backups. These measures can help reduce damage if a website is compromised and make recovery easier.
Website monitoring is equally important. Unusual login attempts, unexpected file changes, slower performance or unfamiliar administrator accounts could indicate that a site has already been breached. Early detection allows administrators to isolate affected systems before attackers can cause greater damage.
The latest findings also highlight a common challenge in website security. While software developers may release fixes quickly after discovering vulnerabilities, many organisations and individual users postpone updates due to compatibility concerns or operational delays. Cybercriminals are well aware of this gap and often launch attacks immediately after patches become public, knowing that many websites remain unprotected.
Security experts describe patch management as one of the most critical aspects of cybersecurity. Regular maintenance, timely updates and continuous monitoring significantly reduce the risk of website compromise.
For businesses, an attack can lead to stolen customer information, disrupted services, reputational damage and financial losses. Even personal blogs or small websites can be hijacked to distribute malware, host phishing pages or participate in larger botnet attacks.
Researchers urge all WordPress users to review their websites immediately, install the latest security updates, audit installed plugins and themes, and remove anything that is no longer required. They also recommend using reputable security plugins and web application firewalls to add another layer of protection.
The renewed attacks serve as a reminder that in today’s digital landscape, cyber threats evolve rapidly. Security patches are only effective when they are installed. For millions of WordPress website owners, acting quickly could be the difference between staying secure and becoming the next victim of a cyberattack.
Also Read: Pakistan seeks Canada’s support on Indus waters treaty