started · updated
WordPress and Joomla websites face increased cyberattacks
Cybercriminals are increasingly targeting websites built on WordPress and Joomla, exploiting critical vulnerabilities. Security experts and agencies, including the US-based CISA, have reported active exploitation of high-risk flaws. Specifically, the Astroid template framework and the JCE content editor have been identified with vulnerabilities carrying a maximum CVSS risk score of 10.0.
Data from security specialist Patchstack indicates a significant rise in threats, with approximately 11,334 new vulnerabilities discovered in the WordPress ecosystem in 2025, representing a 42 percent increase from the previous year. Notably, 91 percent of these vulnerabilities reside in plugins and themes rather than the core software. Furthermore, security service Sansec has reported a campaign targeting over one million WordPress sites.
Experts warn that attackers often exploit newly released vulnerabilities within hours, frequently before patches are available. For administrators, a hack can result in the loss of admin access through deleted accounts or changed credentials. Effective recovery requires a thorough analysis of the entry point and a complete backup of files and databases to prevent attackers from using hidden backdoors to re-enter the system.
Entities
CISA · Joomla · Patchstack · Sansec · WordPress
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 2 SOURCES] The Astroid template framework and JCE content editor have vulnerabilities rated with a maximum CVSS score of 10.0. www.presse-board.de · pressnetwork.de
- [● 2 SOURCES] The number of WordPress vulnerabilities increased by 42 percent compared to the previous year. www.presse-board.de · pressnetwork.de
- [● 2 SOURCES] Approximately 11,334 new security vulnerabilities were identified in the WordPress ecosystem in 2025. www.presse-board.de · pressnetwork.de
- [● 2 SOURCES] 91 percent of WordPress vulnerabilities are located in plugins and themes rather than the core software. www.presse-board.de · pressnetwork.de
- [● 2 SOURCES] Sansec reported a campaign targeting more than one million WordPress websites. www.presse-board.de · pressnetwork.de
- [● 2 SOURCES] The US agency CISA has reported several critical vulnerabilities being actively exploited. www.presse-board.de · pressnetwork.de