Wire · founder news, decoded · regulatory
Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk
◆ Published
20 July 2026
◆ Topic
regulatory
◆ Sectors
◆ Source
◆ Verified
Fusion42 · 20 July 2026 · Fusion42 review
Two critical WordPress vulnerabilities patched last week are now being actively exploited; cybersecurity firms estimate tens of millions of websites remain vulnerable as of Monday, with hackers gaining remote access.
This Wire brief sits within Fusion42's coverage of Cybersecurity. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur reasons over.
◆ The Wire takeaway
If you sell WordPress security, compliance, or managed hosting to SMEs, your phone is ringing this week—tens of millions of unpatched sites are under active attack, and your customer base knows it. The gap between patch release and widespread adoption just became a sales lever: emergency remediation, patch management automation, and vulnerability scanning are now table-stakes upsell.
◆ Related on Wire
- New wp2shell RCE Vulnerability Hits Millions of WordPress Sites, Emergency Patch Released18 July 2026
- WordPress Core "wp2shell" RCE flaws get public exploits, patch now18 July 2026
- Patch now: WordPress REST API bug allows remote code execution20 July 2026
- New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code18 July 2026
- CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV8 July 2026
- CISA warns that multiple vulnerabilities in SharePoint are under exploitation15 July 2026
◆ Topics
Cybersecurity · wordpress-vulnerability · patch-lag · remote-access · web-infrastructure · zero-day-exploitation