It’s Been a Big Week for WordPress Security — Here’s What Small Business Owners Need to Know


If you run a WordPress website, the last seven days have been a busy one for security researchers. Several serious issues have come to light, and hackers are already trying to take advantage of them. None of this means you need to panic, but it’s a good moment to check your site is being looked after properly. Here’s what happened and what it means for you.


1. A serious flaw was found in WordPress itself

Researchers discovered a critical weakness affecting core WordPress software (nicknamed “WP2Shell” in security circles) that could let an attacker take over a site without even needing a password. It affected huge numbers of websites running recent versions of WordPress, so the WordPress team acted fast: they released a fix and, because the risk was so high, pushed it out automatically to affected sites rather than waiting for site owners to update manually.

Why it matters: this is about as serious as WordPress security issues get, because no plugins or weak passwords were needed to exploit it – just an out-of-date version of WordPress itself. If your site auto-updates, you were likely protected already. If it doesn’t, this is exactly the kind of gap a managed WordPress service is built to catch.


2. A hidden backdoor was found in a popular plugin

A widely used video plugin was found to have malicious code slipped into one of its updates, which could have given attackers admin-level access to around 20,000 websites. The good news is that a security firm spotted the tampered code within two hours of it going live and quickly rolled out protection. It’s a reminder that even legitimate, well-known plugins can be compromised without warning.

Why it matters: you can do everything right – choose a reputable plugin, keep it updated – and still be caught out if the plugin developer’s own systems are hacked. The best defence isn’t avoiding plugins altogether, it’s having someone monitoring your site who can react quickly if something like this happens.


3. Online shop checkouts targeted through a funnel-builder plugin

A vulnerability in a popular “funnel builder” plugin, used by more than 40,000 WooCommerce stores, was found being actively exploited to inject code into checkout pages and steal customers’ payment details. A fix is now available, but any store still running the older version remains exposed.

Why it matters: if you sell online, this is the nightmare scenario – customers entering card details on what looks like your normal checkout, while hidden code quietly copies that information. If you use any kind of checkout, funnel, or booking plugin, now’s the time to make sure it’s on the latest version.


4. UK small businesses are being scanned by hackers more than ever

Away from WordPress specifically, new figures show UK small businesses are facing a sharp rise in automated attacks – networks and websites are now being probed by hackers thousands of times a day, up significantly on last year. This has prompted fresh government guidance encouraging smaller firms to take basic protective steps seriously, rather than assuming they’re “too small to be a target.”

Why it matters: these scans aren’t personal – they’re automated bots checking every website they can find for known weaknesses, and they don’t discriminate between a large company and a local shop’s website. The businesses that get hit hardest are usually the ones with unpatched software, because that’s exactly what the bots are hunting for.


The takeaway

None of these stories are a reason to panic, but together they paint a clear picture: WordPress sites need regular attention, not a “set it up once and forget it” approach. Software needs updating, plugins need watching, and someone needs to notice quickly when something looks wrong.

If your website hasn’t had a proper check-up in a while, or you’re not sure who’s keeping an eye on updates and security patches, our WordPress Maintenance service takes care of all of this for you – so a busy news week like this one doesn’t have to mean a stressful one for you.

← Back to Blog