WordPress Under Fire Again: What Small Business Owners Need to Know This Week


It’s been a busy week for WordPress security. Hackers have been actively exploiting a fresh flaw in WordPress itself, and a well-known plugin company got hacked in a way that quietly spread through its own updates. None of this means WordPress is unsafe to use, it’s still the most widely used way to run a website. It just means the sites that stay safe are the ones that keep up with updates rather than leaving them to chance. If your website runs on WordPress, or you’re simply not sure how up to date it is, here’s what happened this week and what it means for you.


WordPress patched a bug hackers were already using

WordPress released an update (version 7.0.3) fixing 12 separate security issues. One of them, a flaw on the login screen, was already being used by attackers before the fix arrived, and could let them run malicious code on an unpatched site.

Why it matters: this affects any WordPress site, no dodgy plugins required. Automated bots scan the internet non-stop looking for sites that haven’t installed the fix yet, often within hours of it becoming public. If your site auto-updates, you’re likely already covered. If you’re not sure, it’s worth logging in and checking, or asking whoever looks after your site to confirm for you.


A trusted plugin company was hacked, and it spread through updates

Plugin maker BdThemes had its update system compromised. Attackers used it to quietly slip a backdoor into seven of the company’s plugins, creating hidden admin accounts on affected sites without anyone needing to click anything. The plugins have since been pulled from the WordPress directory while the issue is fixed.

Why it matters: this is a good reminder that even reputable, long-standing plugins can become a way in if the company behind them is compromised. It’s another reason a site should be checked regularly, not just left to update itself and forgotten.


A second plugin flaw, and it’s a serious one

A popular search plugin, Ajax Search Lite, was found to have a critical security hole, rated 9.8 out of 10 for severity. It’s already been fixed in the latest version.

Why it matters: if this plugin is sitting on your site and hasn’t been updated, it’s effectively an open door. Vulnerabilities this severe tend to get exploited fast once they’re public.


Scammers are getting better at faking your bank, host or suppliers

Away from WordPress itself, security researchers are tracking a fast-growing “phishing-as-a-service” kit that lets even low-skill criminals spin up convincing fake login pages in minutes, complete with tricks to intercept two-factor codes in real time.

Why it matters: small businesses are a favourite target for kits like this, precisely because attackers assume weaker defences and less staff training. A single team member clicking the wrong link, or entering a password into a convincing fake page, can do as much damage as a direct hack on your website. It’s worth a reminder to your team every so often: hover over links before clicking, and go to a site directly rather than through an email link whenever you’re asked to log in.


The takeaway

The thread running through this week’s news is simple: update promptly, and don’t assume a well-known plugin is risk-free forever. If your site is running the latest WordPress core version and up-to-date plugins, you’re already in a much stronger position than most.

If keeping on top of WordPress updates, plugin checks and security patches sounds like one more thing on an already long list, that’s exactly what our WordPress Maintenance service takes off your plate, so your site stays secure without you having to think about it.

← Back to Blog