Hackers began exploiting security vulnerabilities in WordPress plugins shortly after their security updates were released, putting millions of websites at risk of being hacked if their systems are not updated immediately.

TechCrunch reported that the attacks target sites that have not yet installed the latest security updates, as attackers rely on reverse engineering of published updates to discover vulnerabilities and exploit them against sites that are still running old versions.

According to the report, some of these vulnerabilities allow attackers to control the site, execute commands remotely, or upload malicious files, which may lead to the theft of user data or turn the site into a platform for spreading malware.

Cybersecurity experts called on site administrators to install the latest updates immediately, delete unused additions, and activate automatic updates whenever possible, stressing that the period following the publication of any security update is considered the most dangerous because hackers are quick to analyze changes and exploit sites that are late in updating.