Hackers Target Vulnerable WordPress Sites: Are You at Risk?

TL;DR
- Critical vulnerabilities exposed: Hackers are exploiting remote code execution (RCE) flaws in popular plugins like WPCode, LiteSpeed Cache, and WordPress File Manager, allowing unauthenticated attackers to take full control of sites.
- Massive scale of risk: Over 11 million websites are potentially affected by the latest critical disclosures, with 146 new vulnerabilities identified in a single week in May 2026.
- Immediate action required: Site owners must update WPCode to version 2.3.6, LiteSpeed Cache to 7.8, and remove inactive plugins immediately to prevent hijacking.
A New Wave of WordPress Exploits Targets Millions
The WordPress ecosystem is facing a severe security crisis as hackers increasingly exploit critical flaws in widely used plugins to remotely compromise millions of websites. Recent disclosures reveal that attackers can bypass authentication mechanisms and execute arbitrary code, granting them complete server access without needing a password. This surge in activity is not isolated; in 2025 alone, the WordPress ecosystem saw 11,334 new vulnerabilities discovered, marking a 42% increase compared to the previous year. The urgency for website owners is high, as many of these flaws are being actively exploited in the wild.
The Most Dangerous Vulnerabilities Right Now
Several specific vulnerabilities have emerged as the primary targets for attackers due to their high impact and the massive number of installations they affect.
Remote Code Execution in WPCode
The most headline-grabbing disclosure involves an authenticated remote code execution flaw in the WPCode plugin (versions 2.3.5 and earlier). Installed on roughly three million sites, this vulnerability allows a low-level contributor account to push arbitrary PHP code through XML-RPC, effectively granting them full control. The exploit path is straightforward, and the patch (version 2.3.6) is already available, but many sites remain unupdated.
Unauthenticated Access in LiteSpeed Cache and File Manager
Even more alarming are vulnerabilities that do not require a user to be logged in. The LiteSpeed Cache plugin, with over 6 million active installations, contains a privilege escalation flaw allowing unauthenticated users to gain administrator access by manipulating HTTP headers. Similarly, the WordPress File Manager plugin (700,000+ installations) suffered a critical Remote Code Execution (RCE) vulnerability (CVE-2025-1847) that let unauthenticated attackers upload and execute PHP webshells, leading to complete server compromise.
Broken Access Control in Post SMTP
Another critical issue, CVE-2025-24000, affects the Post SMTP plugin. A broken access control mechanism in its REST API allows even low-privileged users to view email logs containing full email contents. Attackers can hijack an administrator account by initiating a password reset, intercepting the reset link from the logs, and claiming admin privileges.
Why Website Owners Are at Risk
The scale of this threat is driven by the sheer ubiquity of the affected software. When a vulnerability exists in a plugin used by millions of sites, it creates a "perfect storm" for attackers. The combined install footprint of the three most critical plugins mentioned above—WPCode, Spectra Gutenberg Blocks, and LiteSpeed Cache—covers over 11 million sites.
Furthermore, the nature of these flaws often bypasses traditional security measures. Issues like SQL injection, cross-site scripting (XSS), and broken access control allow attackers to inject malicious code, steal data, or take over the site entirely if not addressed promptly. Outdated plugins and themes are the primary vector, as they harbor known vulnerabilities that hackers can easily exploit. Many site owners also fall into the trap of leaving inactive plugins installed or using default admin usernames, which further reduces their security posture.
Immediate Steps to Secure Your Website
To protect against these threats, website owners must act immediately. The following steps are critical:
- Update Immediately: If you use WPCode, update to version 2.3.6 today. Similarly, update LiteSpeed Cache to 7.8 and Spectra Gutenberg Blocks to 2.19.26.
- Disable XML-RPC: Since the WPCode exploit runs through XML-RPC, disable or restrict this feature if your site does not require it.
- Audit User Permissions: Review recent contributor and author logins to ensure no unauthorized access has occurred.
- Remove Inactive Plugins: Delete any plugins or themes that are not actively in use to reduce the number of potential entry points for attackers.
- Install Security Plugins: Use reputable security tools like Wordfence or Sucuri Security to enable firewalls, malware scans, and two-factor authentication (2FA).
The Urgency of Patching and Future Outlook
The window for safety is closing. In the week of May 25–31, 2026, 146 new vulnerabilities were disclosed, including 6 critical and 24 high-severity issues. Plugins accounted for 97% of these disclosures, highlighting that the extension ecosystem is the weakest link in WordPress security.
Website owners who delay patching risk their sites being hijacked, used for spam distribution, or completely wiped. The trend of increasing vulnerabilities suggests that 2026 will be a challenging year for WordPress security, with a 42% rise in new flaws compared to 2024. Regular security audits, strong credentials, and limited user permissions are essential to prevent most attacks, but they are not a substitute for timely updates.
Conclusion: Don't Wait for the Hack
The exploitation of these critical flaws is not a theoretical risk; it is an active campaign targeting millions of websites. The combination of remote code execution, privilege escalation, and broken access control in popular plugins creates a severe threat landscape. By updating immediately, disabling unnecessary services, and maintaining a strict security regimen, site owners can protect their digital assets. The cost of inaction is far higher than the few minutes required to update a plugin.
Get All The Latest Updates Delivered Straight To Your Inbox For Free!