Tech News

Tech Business News

  • Home
  • Technology
  • Business
  • News
    • Technology News
    • Local Tech News
    • World Tech News
    • General News
    • News Stories
  • Media Releases
    • Tech Media Releases
    • General Media Releases
  • Advertisers
    • Advertiser Content
    • Promoted Content
    • Sponsored Whitepapers
    • Advertising Options
  • Cyber
  • Reports
  • People
  • Science
  • Articles
    • Opinion
    • Digital Marketing
    • Gaming
    • Guest Publishers
  • About
    • Tech Business News
    • News Contributions -Submit
    • Contact Us
Reading: Millions of Attacks Target Critical WordPress Vulnerability as Exploitation Methods Shift
Share
Font ResizerAa
Tech Business NewsTech Business News
  • Home
  • Technology News
  • Business News
  • News Stories
  • General News
  • World News
  • Media Releases
Search
  • News
    • Technology News
    • Business News
    • Local News
    • News Stories
    • General News
    • World News
    • Global News
  • Media Releases
    • Tech Media Releases
    • General Press
  • Categories
    • Crypto News
    • Cyber
    • Digital Marketing
    • Education
    • Gadgets
    • Technology
    • Guest Publishers
    • IT Security
    • People In Technology
    • Reports
    • Science
    • Software
    • Stock Market
  • Promoted Content
    • Advertisers
    • Promoted
    • Sponsored Whitepapers
  • Contact & About
    • Contact Information
    • About Tech Business News
    • News Contributions & Submissions
Follow US
© 2022 Tech Business News- Australian Technology News. All Rights Reserved.
Tech Business News > IT Security > Millions of Attacks Target Critical WordPress Vulnerability as Exploitation Methods Shift
IT Security

Millions of Attacks Target Critical WordPress Vulnerability as Exploitation Methods Shift

MalCare has recorded more than 3.18 million attempted attacks exploiting a critical WordPress vulnerability across websites protected by its network. The flaw affects versions 4.7 through 7.1.1 and was patched in WordPress 7.1.2, released on September 22.

Matthew Giannelis
Last updated: October 3, 2026 4:45 am
Matthew Giannelis
Share
SHARE

A recently disclosed critical WordPress vulnerability is being targeted at significant scale, with security provider MalCare reporting more than 3.18 million attempted attacks across websites protected by its network.

The vulnerability affects WordPress versions dating back to the 4.7 branch and remained present through WordPress 7.1.1. WordPress released version 7.1.2 on September 22 to address the flaw and urged website operators to update immediately.

The security issue involves an unauthenticated path traversal vulnerability in WordPress page-template handling. Under certain server and theme configurations, an attacker could cause WordPress to include a readable PHP file outside the active theme directory, potentially leading to remote code execution.

Remote code execution vulnerabilities are considered particularly serious because successful exploitation can, under the right conditions, allow an attacker to execute code on a vulnerable server.

MalCare initially reported that its Vulnerability Shield had intercepted more than 5,000 exploitation attempts within hours of attacks beginning. According to a subsequent update from the company, that figure has now climbed to more than 3.18 million.

The figure represents attacks observed and blocked within MalCare’s own customer network and should not be interpreted as the total number of attacks occurring across the wider internet.

MalCare said early attacks predominantly delivered exploit attempts through URLs, but within several days a substantial proportion had shifted towards requests resembling data submitted through website forms.

The change illustrates a familiar problem for website security teams. Once details of a significant vulnerability become public, attackers can alter payloads and delivery methods in an effort to bypass firewall rules and other protections.

MalCare has suggested that artificial intelligence may be contributing to the speed at which malicious requests are being modified, although the company has not provided evidence establishing that AI was responsible for the changing attack patterns.

The wider security risk extends beyond websites that remain unpatched.

Because the vulnerability existed before its public disclosure and subsequent security update, administrators cannot assume that installing the latest WordPress release automatically means a website was never compromised.

Website operators running affected versions should therefore update WordPress immediately, review server and security logs for suspicious activity and conduct a malware or integrity scan where possible.

The latest exploitation figures are another reminder that patching delays can leave even relatively small websites exposed once a serious vulnerability becomes publicly known.

For businesses running WordPress for ecommerce, publishing, customer portals or other critical services, updating the software is only part of the response. Administrators should also check whether there is evidence that exploitation occurred before the vulnerability was patched.

ByMatthew Giannelis
Follow:
Secondary editor and executive officer at Tech Business News. An IT support engineer for 20 years he's also an advocate for cyber security and anti-spam laws.
Previous Article iPhone (Apple) prices Australian's paying more Australians Are Paying Hundreds More for iPhones as Apple Prices Climb
Leave a Comment

Leave a Reply Cancel reply

You must be logged in to post a comment.

MalCare Blocks 3.18M Attacks On Latest WP Core Vulnerability

Tech Articles

Online Privacy - Ways to protect your personal information

Want Complete Online Privacy? Disconnecting From the Internet May Be The Only Certain Option

Complete online privacy is becoming increasingly difficult as websites, apps…

August 8, 2026

How AI Is Changing The Way Businesses Build Websites

Businesses are increasingly using AI website builders such as Lovable,…

August 25, 2026
What Building My Own News Startup Taught Me - Matthew Giannelis

What Building My Own News Startup Taught Me About Journalism, Business and the Internet

Building my own news startup taught me that great journalism…

August 6, 2026

Recent News

Bad Bots Australia Malicious technology
IT Security

Australia Remains A Prime Target For Malicious Bad Bots – 30.2%

5 Min Read
IoT Security Impact 2026
IT Security

The Impact Of IoT On Cybersecurity

9 Min Read
IT Security

Group-IB Opens Latest Digital Crime Resistance Center in Thailand

6 Min Read
AI IT Security
IT Security

How AI Is Making IT Security Defenses Work Harder

12 Min Read
Tech News - Technology Business

Tech Business News

In 2026, technology news is shaping business outcomes faster than ever—driven by AI adoption, rising cyber risk, cloud modernisation, data regulation, and constant platform change.
 
Tech News keeps Australian organisations and industry professionals informed with timely reporting and practical coverage across AI, cybersecurity, cloud, enterprise IT, startups, science, people and business, plus major world and local news impacting the tech sector.
 
Tech Business News publishes news and analysis designed to be clear, relevant, and easy to act on. It supports the industry with technology news reports, whitepaper publishing services, and a range of media, advertising and publishing options 

About

About Us 
Contact Us 
Privacy Policy
Copyright Policy
Terms & Conditions

October, 03, 2026

Contact

Tech Business News
Melbourne, Australia
Werribee 3030
Phone: +61 431401041

Hours : Monday to Friday, 9am 530-pm.

Tech News

© Copyright Tech Business News 

Latest Australian Tech News – 2026

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?