Audio By Carbonatix
A security flaw in the WordPress blogging software has let hackers attack and deface tens of thousands of sites.
One estimate suggests more than 1.5 million pages on blogs have been defaced.
The security firm that found the vulnerability said some hackers were now trying to use it to take over sites rather than just spoil pages.
WordPress urged site owners to update software to avoid falling victim.
Feeding frenzy
The vulnerability is found in an add-on for the WordPress blogging software that was introduced in versions released at the end of 2016.
Security firm Sucuri found the "severe" bug and informed WordPress about it on 20 January.
In a blogpost, WordPress said it delayed going public about the flaw so it could prompt hosting firms to update their software to a fixed version.
The patched version of WordPress was formally released on 26 January and led to many sites and blogs automatically applying the update.
However, many blogs have not followed suit leaving them open to defacement attacks.
Security firm WordFence said it had seen evidence that 20 hacker groups were trying to meddle with vulnerable sites. About 40,000 blogs are believed to have been hit.
The vulnerability had set off a "feeding frenzy" among hacker groups, WordFence founder Mark Maunder told the Bleeping Computer tech news site.
"During the past 48 hours we have seen over 800,000 attacks exploiting this specific vulnerability across the WordPress sites we monitor," he added.
Sucuri said some hacker groups had moved on from defacement to attempts to use the bug to hijack sites for their own ends.
"Attackers are starting to think of ways to monetise this vulnerability," wrote Sucuri founder Daniel Cid. "Defacements don't offer economic returns, so that will likely die soon."
Hackers were keen to use the vulnerable sites as proxies for spam or malware campaigns, he said.
Latest Stories
-
COMAC and CBOD hint at strike over illegal diversion of LPG Fund to GCMC
8 minutes -
Women of Valour 2026 launched as survivors share abuse stories
10 minutes -
Smuggled cooking oil bust aimed at protecting Ghana’s economy—GRA boss
22 minutes -
Mamprobi Polyclinic baby theft suspect to appear in court
36 minutes -
Prudential Bank, Rana Motors, power music, culture and community at The Blend Festival 2026
38 minutes -
True love found again: Davisson-Konu recounts reunion with JHS sweetheart
38 minutes -
Kwadaso MCE leads drive to strengthen TVET education in Ashanti region
40 minutes -
Dr Ishmael Norman urges Nitiwul to apologise over ‘unfair’ remarks on Ghana’s defence strength
43 minutes -
John Dumelo to provide free cocoa drinks to Basic School Pupils in Ayawaso West
45 minutes -
Mfantsipim sets out five-pillar reform agenda ahead of 150th anniversary
46 minutes -
World Cup 2026: Ghana-England match in limbo
48 minutes -
Gov’t releases GH₵855m to pay cocoa farmers as Majority backs sweeping reforms to revive COCOBOD
54 minutes -
Burkina Faso attack: Nitiwul urges government to appoint Defence Minister
58 minutes -
Roads Ministry to take over COCOBOD projects amid GH¢26bn commitments — Adongo
58 minutes -
Old Tafo MP drags deputy COCOBOD CEO to CHRAJ over conflict of interest
1 hour
