> ## Content Index
> Fetch the complete content index at: https://ryanbrooks.net/llms.txt
> Use this file to discover other available public pages before exploring further.

# New WordPress Vulnerability Results in ~2 Million Defaced Sites
- URL: https://ryanbrooks.net/new-wordpress-vulnerability-results-in-2-million-defaced-sites/
- Published: 2017-02-12T06:14:43.000Z
- Updated: 2017-02-12T06:14:43.000Z
- Author: Ryan Brooks
- Tags: Interesting Links, Security, Website, 2017, Ars Technica, internet, technology, websites, #wp, #wp-post, #Import 2026-07-17 22:34

The vulnerability was patched in WordPress v4.7.2 two weeks ago, but millions of sites haven't yet updated. This leaves them open to a [vulnerability in the WordPress REST API](https://blog.sucuri.net/2017/02/content-injection-vulnerability-wordpress-rest-api.html?ref=ryanbrooks.net), which can allow malicious actors to edit any post on a site.

[Ars Technica](https://arstechnica.com/security/2017/02/virally-growing-attacks-on-unpatched-wordpress-sites-affects-2m-pages/?ref=ryanbrooks.net) has a very nice writeup on the effects of the exploit, which has resulted in the defacement of a staggering number of websites (including the websites of Glenn Beck, the Utah Office of Tourism, and even the official Suse Linux site). [Sucuri](https://blog.sucuri.net/2017/02/wordpress-rest-api-vulnerability-abused-in-defacement-campaigns.html?ref=ryanbrooks.net) and [Wordfence](https://www.wordfence.com/blog/2017/02/rapid-growth-in-rest-api-defacements/?ref=ryanbrooks.net) also have very good articles about the effects of the vulnerability.

If you have a WordPress site, you should immediately check to make sure you're on the latest version (v4.7.2).