Actively exploited WordPress bug puts millions of sites at risk
XSS vulnerability allows attackers to take full control of unpatched sites. — Millions of websites running WordPress are at risk of hijacking attacks thanks to a vulnerability that is actively being exploited in the wild …
Context & Ripple Effects
This 2015 report lands mid-pattern rather than at its start or end: weeks later Ars Technica tracked [[a:833149|a malware campaign hijacking thousands of WordPress sites at a rate of thousands of new infections daily]], showing exactly what active exploitation of unpatched installs looks like at scale. The same year brought Joomla's emergency patch for a critical SQL-injection flaw affecting millions of sites, confirming the exposure is CMS-wide, not WordPress-specific.
First-order effects
- Site owners running unpatched WordPress face immediate site takeover through the exploited XSS flaw, since attacks are already live rather than theoretical.
- WordPress core maintainers are pushed into emergency patch-and-disclose mode while administrators race to update millions of self-hosted installs.
Second-order effects
- The attack surface extends beyond core: LiteSpeed Cache, the top WordPress acceleration plugin, would later leave over two million sites open to takeover through a plugin flaw, so every popular extension becomes part of the same risk pool.
- Hosting providers and managed-WordPress services gain a selling point in automatic patching, because the long tail of self-administered sites is demonstrably the slowest to fix.
Third-order effects
- If the pattern holds — core bugs, plugin takeovers, and rival CMS flaws like Drupal's highly critical remote-code-execution warning all recurring for years — CMS security becomes a shared-infrastructure problem where patch latency across millions of independent operators, not any single vulnerability, is the durable weakness.
- That dynamic favors consolidation toward platforms with centralized, mandatory updates, pressuring the open-source CMS model to adopt managed-update defaults to keep the long tail patched.
The trend: Content-management systems keep cycling through actively exploited core and plugin flaws, making the patching lag of millions of self-managed sites a permanent, structural attack surface.