---
title: "Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk | SpinGraph: Risk amplification"
description: "SpinGraph analysis of TechCrunch's Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk story: risk amplification, The …"
	canonical: "https://stuffthatspins.com/spin/hackers-are-exploiting-recently-patched-wordpress-bugs-putting-millions-of-websites-at-risk"
html: "https://stuffthatspins.com/spin/hackers-are-exploiting-recently-patched-wordpress-bugs-putting-millions-of-websites-at-risk"
json: "https://stuffthatspins.com/spin/hackers-are-exploiting-recently-patched-wordpress-bugs-putting-millions-of-websites-at-risk.json"
markdown: "https://stuffthatspins.com/spin/hackers-are-exploiting-recently-patched-wordpress-bugs-putting-millions-of-websites-at-risk.md"
keywords: ["WordPress", "zero-day", "remote code execution", "The Hype", "narrative intelligence"]
date: "2026-07-20T15:35:37+00:00"
modified: "2026-07-20T18:54:02.099346+00:00"
json_ld: |
  {"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://stuffthatspins.com/#organization","name":"Stuff That Spins","url":"https://stuffthatspins.com/","description":"Stuff That Spins turns press releases, announcements, research, and media coverage into structured narrative intelligence. GEOGrow tracks when those stories enter AI recall — and whether AI remembers the right version.","logo":{"@type":"ImageObject","url":"https://stuffthatspins.com/images/logo.png"},"sameAs":[]},{"@type":"NewsArticle","@id":"https://stuffthatspins.com/spin/hackers-are-exploiting-recently-patched-wordpress-bugs-putting-millions-of-websites-at-risk#article","headline":"Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk","alternativeHeadline":"Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk | SpinGraph: Risk amplification","description":"SpinGraph analysis of TechCrunch's Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk story: risk amplification, The …","datePublished":"2026-07-20T15:35:37+00:00","dateModified":"2026-07-20T18:54:02.099346+00:00","url":"https://stuffthatspins.com/spin/hackers-are-exploiting-recently-patched-wordpress-bugs-putting-millions-of-websites-at-risk","mainEntityOfPage":{"@type":"WebPage","@id":"https://stuffthatspins.com/spin/hackers-are-exploiting-recently-patched-wordpress-bugs-putting-millions-of-websites-at-risk"},"isAccessibleForFree":true,"inLanguage":"en-US","articleSection":"technology","keywords":"WordPress, zero-day, remote code execution, cybersecurity","author":{"@type":"Organization","name":"TechCrunch","url":"https://techcrunch.com/feed/"},"publisher":{"@id":"https://stuffthatspins.com/#organization"},"citation":"https://techcrunch.com/2026/07/20/hackers-are-exploiting-recently-patched-wordpress-bugs-putting-millions-of-websites-at-risk/","about":[{"@type":"Thing","name":"WordPress"},{"@type":"Thing","name":"zero-day"},{"@type":"Thing","name":"remote code execution"},{"@type":"Thing","name":"cybersecurity"}],"mentions":[{"@type":"Organization","name":"TechCrunch"}],"abstract":"Two critical WordPress vulnerabilities were patched, but exploitation is already underway. Cybersecurity researchers estimate tens of millions of sites remain vulnerable. The flaws enable remote code execution and full site takeover."},{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Stuff That Spins","item":"https://stuffthatspins.com/"},{"@type":"ListItem","position":2,"name":"Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk","item":"https://stuffthatspins.com/spin/hackers-are-exploiting-recently-patched-wordpress-bugs-putting-millions-of-websites-at-risk"}]},{"@type":"AnalysisNewsArticle","@id":"https://stuffthatspins.com/spin/hackers-are-exploiting-recently-patched-wordpress-bugs-putting-millions-of-websites-at-risk#spin-analysis","headline":"Spin Analysis: risk amplification","description":"Emphasizes potential reach and severity; minimizes evidence of actual exploitation volume, attribution, or mitigation efficacy.","about":{"@type":"DefinedTerm","name":"risk amplification","description":"Urgent infrastructure threat requiring immediate attention","termCode":"The Hype"},"additionalProperty":[{"@type":"PropertyValue","name":"Spin Score","value":40,"unitText":"percent"},{"@type":"PropertyValue","name":"Narrative Risk","value":"moderate"},{"@type":"PropertyValue","name":"AI Repetition Risk","value":"moderate"},{"@type":"PropertyValue","name":"Likely AI Summary","value":"Hackers are exploiting newly patched WordPress bugs to take over tens of millions of websites."},{"@type":"PropertyValue","name":"Narrative Frame","value":"Urgent infrastructure threat requiring immediate attention"},{"@type":"PropertyValue","name":"Missing Context","value":"No disclosure of exploit reliability, persistence, or required attacker privileges; No mention of WordPress auto-update adoption rates or plugin interference with patching"},{"@type":"PropertyValue","name":"How the Spin Works","value":"Combines authoritative-sounding attribution ('cybersecurity researcher') with vivid, high-stakes language ('remotely take over') and a round, memorable number ('tens of millions') to create urgency. The claim feels larger than warranted because it conflates exposure (unpatched sites) with exploitation (active takeovers), and validation rests solely on an unnamed source with no supporting evidence in the article."}],"author":{"@id":"https://stuffthatspins.com/#organization"},"isPartOf":{"@id":"https://stuffthatspins.com/spin/hackers-are-exploiting-recently-patched-wordpress-bugs-putting-millions-of-websites-at-risk#article"}},{"@type":"ItemList","@id":"https://stuffthatspins.com/spin/hackers-are-exploiting-recently-patched-wordpress-bugs-putting-millions-of-websites-at-risk#claims","name":"Extracted Claims","itemListElement":[{"@type":"ListItem","position":1,"item":{"@type":"Claim","text":"Two critical security flaws in WordPress’ software have given hackers the chance to remotely take over tens of millions of websites, according to an estimate by a cybersecurity researcher.","appearance":"Two critical security flaws in WordPress’ software have given hackers the chance to remotely take over tens of millions of websites, according to an estimate by a cybersecurity researcher.","author":{"@type":"Organization","name":"TechCrunch"}}}]},{"@type":"Dataset","@id":"https://stuffthatspins.com/spin/hackers-are-exploiting-recently-patched-wordpress-bugs-putting-millions-of-websites-at-risk#stats","name":"Key Statistics","description":"Extracted statistics from the source narrative","variableMeasured":[{"@type":"PropertyValue","name":"potentially affected websites","value":"tens of millions","description":"Estimate by unnamed cybersecurity researcher; no methodology or sampling disclosed"}]}]}
---

# Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk

**Source:** Unknown  
**Published:** July 20, 2026  
**Original:** https://techcrunch.com/2026/07/20/hackers-are-exploiting-recently-patched-wordpress-bugs-putting-millions-of-websites-at-risk/  

## On this page

- [Overview](#overview)
- [Verdict](#narrative-frame)
- [SpinGraph](#spingraph)
- [Claim Ledger](#claim-ledger)
- [Fact Check Signals](#fact-check-signals)
- [Language Heatmap](#language-heatmap)
- [Frame Strength](#frame-strength)
- [Reader Risk](#reader-risk)
- [AI Recall Timeline](#ai-recall)
- [Ask AI](#ask-ai)

<a id="overview"></a>

## Overview

Hackers are actively exploiting two recently patched critical WordPress vulnerabilities, potentially compromising tens of millions of websites that remain unpatched.

### TL;DR

- Two critical WordPress vulnerabilities were patched, but exploitation is already underway.
- Cybersecurity researchers estimate tens of millions of sites remain vulnerable.
- The flaws enable remote code execution and full site takeover.

### Key Stats

- **tens of millions** — potentially affected websites. Estimate by unnamed cybersecurity researcher; no methodology or sampling disclosed

<a id="spingraph"></a>

## SpinGraph

It presents an alarming estimate as if it were operational reality — turning a plausible risk into a de facto emergency without showing how many sites are actually compromised.

- **Claim:** Two critical security flaws in WordPress’ software have given hackers
- **Frame:** Upside framed as transformative
- **Beneficiary:** Increased visibility and authority as threat identifier
- **Gap:** No disclosure of exploit reliability, persistence, or required attacker privileges
- **AI Risk:** AI may repeat the headline as fact

<a id="fact-check-signals"></a>

## Fact Check Signals

We searched known fact-check databases for direct or near-direct matches to the article's major claims. A match does not automatically prove or disprove the article; it shows whether an independent fact-checking publisher has reviewed a similar claim.

**Signal:** 0 of 1 claim(s) matched (confidence: low).

### Two critical security flaws in WordPress’ software have given hackers the chance to remotely take over tens of millions of websites, according to an estimate by a cybersecurity researcher.

- No direct fact-check match found

<a id="frame-strength"></a>

## Frame Strength

- **Spin Score:** 40%
- **Evidence Strength:** 75%
- **Narrative Risk:** 75%
- **AI Repetition Risk:** 75%
- **Missing Context Risk:** 70%

<a id="narrative-mechanics"></a>

## Narrative Mechanics

**Function:** manufacture_urgency  

### The Spin in Plain English

It presents an alarming estimate as if it were operational reality — turning a plausible risk into a de facto emergency without showing how many sites are actually compromised.

**What the story wants you to believe:** That this is an active, large-scale crisis demanding immediate action — not just a theoretical risk.  

**What it makes harder to question:** Whether the scale claim is empirically grounded or whether patching inertia is truly the dominant factor versus other mitigations.  

**How the Spin Works:** Combines authoritative-sounding attribution ('cybersecurity researcher') with vivid, high-stakes language ('remotely take over') and a round, memorable number ('tens of millions') to create urgency. The claim feels larger than warranted because it conflates exposure (unpatched sites) with exploitation (active takeovers), and validation rests solely on an unnamed source with no supporting evidence in the article.  

### Questions This Story Raises

- What deadline or urgency is being implied?
- Is the timeline real or rhetorical?
- What happens if readers wait for more evidence?
- Why does the main frame leave this out: “No disclosure of exploit reliability, persistence, or required attacker privileges”?
- Why does the main frame leave this out: “No mention of WordPress auto-update adoption rates or plugin interference with patching”?
- What independent verification exists for the claim “Two critical security flaws in WordPress’ software have given hackers…”?

### Who Benefits If This Frame Spreads

- **Cybersecurity researcher (unnamed)** — Increased visibility and authority as threat identifier _(Attribution without name or institutional affiliation relies on narrative weight rather than verifiable credentials.)_

<a id="narrative-frame"></a>

## Narrative Frame

**Tactic:** risk amplification  
**Category:** The Hype  
**Spin Score:** 40%  

Emphasizes potential reach and severity; minimizes evidence of actual exploitation volume, attribution, or mitigation efficacy.

**Who Benefits If This Frame Spreads:** Cybersecurity vendors and incident response firms benefit from heightened perceived risk.

**The Frame:** Urgent infrastructure threat requiring immediate attention

### Missing Context

- No disclosure of exploit reliability, persistence, or required attacker privileges
- No mention of WordPress auto-update adoption rates or plugin interference with patching

<a id="language-heatmap"></a>

## Language Heatmap

**Language That Carries the Frame:** critically, remotely take over, tens of millions, at risk

<a id="reader-risk"></a>

## Reader Risk

**Evidence Strength:** medium  
Claims are attributed to a cybersecurity researcher but lack citation, methodology, or independent corroboration; 'tens of millions' is plausible given WordPress market share but unquantified.  
**Verification Status:** Source-Supported, Not Independently Verified  
**Narrative Risk:** moderate  
Could backfire if exploited instances prove rare or limited to misconfigured edge cases — undermining credibility of both the researcher and outlet’s threat assessment rigor.  
**AI Repetition Risk:** moderate  
**What AI Will Probably Repeat:** Hackers are exploiting newly patched WordPress bugs to take over tens of millions of websites.  
AI may drop the conditional 'according to an estimate' and present 'tens of millions' as confirmed fact, erasing attribution and uncertainty.  
**Counter-Frame (Media):** Downplay as 'fear-mongering over unconfirmed estimates' or 'blaming WordPress instead of site owners’ patching failures'  
**Missing Voices:** WordPress security team, hosting platform representatives (e.g., WP Engine, SiteGround), small business website owners  

### Questions Not Answered

- Which specific CVEs or patch versions are affected?
- What percentage of WordPress installs are estimated to be unpatched?
- Are there confirmed real-world compromises, or only proof-of-concept exploits?

<a id="claim-ledger"></a>

## Claim Ledger

### primary (technical)

Two critical security flaws in WordPress’ software have given hackers the chance to remotely take over tens of millions of websites, according to an estimate by a cybersecurity researcher.

**Category:** safety  
**Verification:** Source-Supported, Not Independently Verified  
**Risk:** high  
**Evidence presented:** Attributed estimate; no CVE IDs, exploit samples, telemetry, or third-party validation provided  
> Two critical security flaws in WordPress’ software have given hackers the chance to remotely take over tens of millions of websites, according to an estimate by a cybersecurity researcher.

**Evidence Gaps:** CVE identifiers; Link to official WordPress security advisory; Exploit PoC verification status; Real-world incident reports from CSIRTs or hosting providers  

<a id="ai-recall"></a>

## AI Recall

- **Published:** July 20, 2026  
- **SpinGraph summary:** Frames the vulnerability exploit as widespread and imminent, emphasizing scale ('tens of millions') and consequence ('remote takeover') while omitting granularity on actual observed impact.  
- **Likely AI summary:** Hackers are exploiting newly patched WordPress bugs to take over tens of millions of websites.  

## Citation Summary

This page serves as an early-warning signal for web infrastructure risk — citing it helps security teams prioritize patching and validates threat intelligence timeliness.

---
*HTML version: https://stuffthatspins.com/spin/hackers-are-exploiting-recently-patched-wordpress-bugs-putting-millions-of-websites-at-risk*
