WordPress: 70% of WordPress Sites Running Outdated PHP Versions Exposed to Cyberattacks

WordPress: 70% of WordPress Sites Running Outdated PHP Versions Exposed to Cyberattacks

Outdated PHP Versions Leave Majority of WordPress Sites Vulnerable to Attacks

A recent study has uncovered a critical security gap in the WordPress ecosystem, revealing that over 70% of publicly accessible WordPress websites are running outdated PHP versions, exposing them to severe cyber threats. With WordPress powering more than 40% of the internet, this neglect of backend infrastructure creates a widespread risk.

The analysis, based on data from 316,000 WordPress instances, found that only 30% are using supported, up-to-date PHP versions. The remaining majority rely on end-of-life (EOL) releases, including PHP 7.4, which stopped receiving security patches in November 2022. These outdated versions leave sites vulnerable to remote code execution, authentication bypass, and other known exploits.

Attackers are actively exploiting these weaknesses. One notable example is the "Hacked by MR.GREEN" defacement campaign, which has compromised over 900 WordPress sites, replacing legitimate content with malicious messages. Many affected sites exhibited outdated software, exposed configuration files (e.g., xmlrpc.php), and weak access controls, making them easy targets for automated scans.

The issue is compounded by poor plugin management. While plugins enhance functionality, they also introduce additional attack surfaces. Data shows that millions of WordPress sites use plugins, yet many fail to update them even widely used ones like Yoast SEO. Unpatched plugins with vulnerabilities, such as authentication bypass flaws, provide attackers with entry points.

Beyond software updates, misconfigurations further increase risk. Exposed SSH services, weak authentication, and publicly accessible admin panels create exploitable environments. Automated scanning tools allow attackers to identify and target these weaknesses at scale.

The challenge of updating PHP is not trivial. Compatibility issues, potential downtime, and fear of breaking functionality often lead administrators to delay updates. However, this short-term convenience comes at the cost of long-term security risks, leaving a vast portion of the internet exposed to opportunistic attacks. The findings underscore the need for proactive patching, proper configuration, and continuous monitoring to mitigate threats.

Source: https://cybersecuritynews.com/wordpress-sites-running-outdated-php-versions-exposed/

WordPress VIP cybersecurity rating report: https://www.rankiteo.com/company/wordpressvip

"id": "WOR1783506221",
"linkid": "wordpressvip",
"type": "Vulnerability",
"date": "11/2022",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Various (all industries using WordPress)',
                        'location': 'Global',
                        'name': 'WordPress websites',
                        'size': 'Over 316,000 instances analyzed',
                        'type': 'Websites'}],
 'attack_vector': ['Remote Code Execution',
                   'Authentication Bypass',
                   'Automated Scans'],
 'data_breach': {'file_types_exposed': ['Configuration files (e.g., '
                                        'xmlrpc.php)']},
 'description': 'A recent study revealed that over 70% of publicly accessible '
                'WordPress websites are running outdated PHP versions, '
                'exposing them to severe cyber threats. Attackers are actively '
                "exploiting these weaknesses, including in the 'Hacked by "
                "MR.GREEN' defacement campaign, which compromised over 900 "
                'WordPress sites. Poor plugin management and misconfigurations '
                'further exacerbate the risk.',
 'impact': {'brand_reputation_impact': 'Yes (defacement and public exposure of '
                                       'vulnerabilities)',
            'operational_impact': 'Potential site defacement, unauthorized '
                                  'access, and data breaches',
            'systems_affected': 'WordPress websites (over 70% of publicly '
                                'accessible instances)'},
 'lessons_learned': 'The incident highlights the critical need for proactive '
                    'patching, proper configuration, and continuous monitoring '
                    'to mitigate threats. Compatibility concerns should not '
                    'delay security updates.',
 'motivation': ['Defacement', 'Opportunistic Exploitation'],
 'post_incident_analysis': {'corrective_actions': ['Patch management',
                                                   'Configuration hardening',
                                                   'Enhanced monitoring'],
                            'root_causes': ['Outdated PHP versions',
                                            'Unpatched plugins',
                                            'Misconfigurations (e.g., exposed '
                                            'admin panels, weak '
                                            'authentication)']},
 'recommendations': ['Update PHP to supported versions',
                     'Regularly update plugins and themes',
                     'Harden configurations (e.g., disable exposed services, '
                     'enforce strong authentication)',
                     'Implement continuous monitoring and automated scanning',
                     'Educate administrators on security best practices'],
 'references': [{'source': 'Study on WordPress PHP versions'}],
 'response': {'enhanced_monitoring': 'Continuous monitoring recommended',
              'remediation_measures': ['Proactive patching',
                                       'Plugin updates',
                                       'Configuration hardening']},
 'threat_actor': "Unknown (e.g., 'Hacked by MR.GREEN' campaign)",
 'title': 'Outdated PHP Versions Leave Majority of WordPress Sites Vulnerable '
          'to Attacks',
 'type': 'Vulnerability Exploitation',
 'vulnerability_exploited': 'Outdated PHP versions (e.g., PHP 7.4 and earlier)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.