Facebook
Britain's News Portal
Around The Clock
BREAKING
Loading latest headlines…

Millions of UK Websites at Risk as Hackers Exploit WordPress Flaws

Cybersecurity experts warn that hackers are actively exploiting recently patched critical vulnerabilities in WordPress software. This puts tens of millions of websites globally, including many in the UK, at risk of complete remote takeover.

  • Two critical security flaws in WordPress versions 6.9.0-6.9.4 and 7.0.0-7.0.1 are being actively exploited.
  • Estimates suggest up to 90 million WordPress websites could still be vulnerable worldwide.
  • The flaws allow hackers to gain full remote control over affected websites.
  • WordPress issued immediate patches last week and enabled forced updates where possible.
  • UK businesses and individuals running WordPress sites are urged to update immediately.

The digital landscape of millions of UK websites is under threat, with hackers exploiting critical vulnerabilities in WordPress that could grant them complete remote control over sites worldwide. While some patches have been issued by WordPress, experts warn that a substantial number of sites remain exposed, posing significant risks to UK businesses and consumers.

According to cybersecurity companies including Patchstack, Hexastrike, and WatchTowr, malicious actors are already taking advantage of the security gaps in versions of WordPress from 6.9.0 through 7.0.1. Although over 400 million websites run these flawed versions, this number likely includes many that have been patched since the vulnerabilities were identified.

Cybersecurity consultant Daniel Card's analysis of approximately 4,200 WordPress sites suggests that less than 15% are currently vulnerable. Applying this projection to the overall WordPress ecosystem could mean around 90 million websites worldwide remain at risk. One of the critical bugs, known as WP2Shell, was discovered and reported by Adam Kues of Searchlight Cyber, and its combination with another flaw presents a significant threat, enabling hackers to execute arbitrary code and gain full control.

The implications for UK businesses and consumers are considerable, given that many SMEs, e-commerce platforms, and personal blogs rely on WordPress. A successful attack could lead to data breaches, website defacement, malware distribution, or the compromise of sensitive customer information. The ICO would likely investigate any significant data breaches resulting from these vulnerabilities, potentially imposing fines under GDPR regulations.

While some progress has been made in securing vulnerable sites, experts stress that immediate action is necessary for site owners to update to the latest WordPress version and implement additional cybersecurity measures such as web application firewalls. The ongoing threat serves as a reminder of the constant need for vigilance in the digital landscape.

Why this matters: This situation poses a direct threat to UK businesses and individuals who rely on WordPress for their online presence, risking data breaches, operational disruption, and financial losses. It underscores the critical importance of timely software updates for digital security.

What this means for you: What this means for you: If you operate a website using WordPress, it is crucial to update your software to the latest version immediately to protect against potential hacking. As a consumer, be aware that websites you visit could be affected, so exercise caution with personal information online.

Related Articles

Get the news that matters.

Join thousands of readers getting the best of British news straight to their inbox.