
Hackers attacking WordPress websites using a recently fixed flaw
Security firms confirmed attackers are exploiting two WordPress flaws patched July 17 in version 7.0.2. Called WP2Shell, the bug chain lets hackers take full control of websites without any login. Public attack code appeared July 19. WordPress forced automatic updates where it could; Cloudflare is blocking known attacks.
Published