A recently disclosed critical WordPress vulnerability is being targeted at significant scale, with security provider MalCare reporting more than 3.18 million attempted attacks across websites protected by its network.
The vulnerability affects WordPress versions dating back to the 4.7 branch and remained present through WordPress 7.1.1. WordPress released version 7.1.2 on September 22 to address the flaw and urged website operators to update immediately.
The security issue involves an unauthenticated path traversal vulnerability in WordPress page-template handling. Under certain server and theme configurations, an attacker could cause WordPress to include a readable PHP file outside the active theme directory, potentially leading to remote code execution.
Remote code execution vulnerabilities are considered particularly serious because successful exploitation can, under the right conditions, allow an attacker to execute code on a vulnerable server.
MalCare initially reported that its Vulnerability Shield had intercepted more than 5,000 exploitation attempts within hours of attacks beginning. According to a subsequent update from the company, that figure has now climbed to more than 3.18 million.
The figure represents attacks observed and blocked within MalCare’s own customer network and should not be interpreted as the total number of attacks occurring across the wider internet.
MalCare said early attacks predominantly delivered exploit attempts through URLs, but within several days a substantial proportion had shifted towards requests resembling data submitted through website forms.
The change illustrates a familiar problem for website security teams. Once details of a significant vulnerability become public, attackers can alter payloads and delivery methods in an effort to bypass firewall rules and other protections.
MalCare has suggested that artificial intelligence may be contributing to the speed at which malicious requests are being modified, although the company has not provided evidence establishing that AI was responsible for the changing attack patterns.
The wider security risk extends beyond websites that remain unpatched.
Because the vulnerability existed before its public disclosure and subsequent security update, administrators cannot assume that installing the latest WordPress release automatically means a website was never compromised.
Website operators running affected versions should therefore update WordPress immediately, review server and security logs for suspicious activity and conduct a malware or integrity scan where possible.
The latest exploitation figures are another reminder that patching delays can leave even relatively small websites exposed once a serious vulnerability becomes publicly known.
For businesses running WordPress for ecommerce, publishing, customer portals or other critical services, updating the software is only part of the response. Administrators should also check whether there is evidence that exploitation occurred before the vulnerability was patched.

