Wordpress is undoubtedly the most popular CMS platform, in the sense that it's the most widely used, but it’s often a victim of its own success because this popularity alone makes it a target. The vast number of users offers up a huge ‘attack surface’ for hackers. Its heavy reliance on over 50,000 third party plugins and templates also adds vulnerabilities, from poorly written code to security ‘back-doors’ deliberately built in by rogue developers – beware the five dollar plugin from a Russian or Chinese developer.

Hacks happen more or less a constantly with Wordpress, but the most recent (Friday 17th July) has put over tens of millions of sites at risk according to cyber security experts.

"Last week, Wordpress patched two critical security flaws, urging people who run its software on their websites to update it “immediately.” The vulnerabilities are so severe that WordPress enabled forced updates where possible. Since then, cybersecurity companies Patchstack, Hexastrike, and WatchTowr have all warned that hackers are exploiting the vulnerabilities in the wild, meaning they are taking over websites that are still running susceptible versions of WordPress." 

Lorenzo Franceschi-Bicchierai, Senior Writer, TechCrunch.

At the moment, it's not completely clear how many sites are at risk, but the vulnerable versions of Wordpress are from 6.9.0 to 7.0.1 which, according to Wordpress's own statistics, is some 400 million sites, but this probably includes sites that have been patched recently. Cybersecurity expert Daniel Card, estimated that between 10% and 15% of sites are vulnerable based on his research of a sample of 3,500 but this is still a significant number - around 90 million.

Wordpress has issued some automatic updates and Megan Fox [not that one] a spokesperson for Automattic, the company that runs Wordpress, commented that 'all sites hosted by Automattic, were protected even before the release. When the code updates were published, we deployed them immediately across millions of sites.' WordPress developers released a patch for two vulnerabilities 'an SQL injection bug tracked as CVE-2026-60137, and a REST API batch-route confusion bug, tracked as CVE-2026-63030'. However, when the bugs are paired, as reported by several cybersecurity experts such as Searchlight Cyber, Knott and The Register, it allows hackers to take full control of vulnerable websites.

"By the early hours of Saturday morning, successful exploitation was already well underway, initially using public exploit code to exfiltrate hashed credentials, with remote code execution following once additional details were made public. From our vantage point across a global client base, we are seeing widespread impact of this vulnerability across organizations of every size and every vertical.”

Knott, Security Research.

Security breaches typically affect out of date plugins - highlighting that any used in a site need to be patched constantly to be kept up to date - but this most recent hack affected Wordpress directly so it's vital that if you do have a Wordpress site, it needs upgrading to at least 6.9.5 which contains fixes for both flaws.

Alternatively, maybe it's time to consider moving to a more secure platform... such as Umbraco!