The digital landscape of millions of UK websites is under threat, with hackers exploiting critical vulnerabilities in WordPress that could grant them complete remote control over sites worldwide. While some patches have been issued by WordPress, experts warn that a substantial number of sites remain exposed, posing significant risks to UK businesses and consumers.
According to cybersecurity companies including Patchstack, Hexastrike, and WatchTowr, malicious actors are already taking advantage of the security gaps in versions of WordPress from 6.9.0 through 7.0.1. Although over 400 million websites run these flawed versions, this number likely includes many that have been patched since the vulnerabilities were identified.
Cybersecurity consultant Daniel Card's analysis of approximately 4,200 WordPress sites suggests that less than 15% are currently vulnerable. Applying this projection to the overall WordPress ecosystem could mean around 90 million websites worldwide remain at risk. One of the critical bugs, known as WP2Shell, was discovered and reported by Adam Kues of Searchlight Cyber, and its combination with another flaw presents a significant threat, enabling hackers to execute arbitrary code and gain full control.
The implications for UK businesses and consumers are considerable, given that many SMEs, e-commerce platforms, and personal blogs rely on WordPress. A successful attack could lead to data breaches, website defacement, malware distribution, or the compromise of sensitive customer information. The ICO would likely investigate any significant data breaches resulting from these vulnerabilities, potentially imposing fines under GDPR regulations.
While some progress has been made in securing vulnerable sites, experts stress that immediate action is necessary for site owners to update to the latest WordPress version and implement additional cybersecurity measures such as web application firewalls. The ongoing threat serves as a reminder of the constant need for vigilance in the digital landscape.