Jessica Entwistle
July 22 2026
Hackers are actively exploiting two recently patched critical vulnerabilities in WordPress, putting tens of millions of websites at risk of remote takeover. TechCrunch reports that the flaws, which have now been addressed in updated versions of WordPress core software, are being targeted by attackers seeking to gain unauthorised access to vulnerable sites. A cybersecurity researcher estimates that the vulnerabilities affect a significant proportion of the WordPress install base, and exploitation activity has been observed in the wild following public disclosure of the patches. WordPress powers approximately 43% of all websites globally, making it one of the most widely deployed content management systems in use today. The speed at which attackers have moved to exploit these disclosed vulnerabilities underscores the narrow window organisations have to apply patches before active compromise attempts begin.
The operational risk is straightforward: any UK organisation running WordPress sites that have not yet applied the latest security updates is exposed to remote compromise. This includes corporate websites, customer portals, marketing sites, internal knowledge bases and e-commerce platforms. For organisations managing multiple WordPress instances, particularly where patching responsibility is distributed across marketing, IT and third-party agencies, there is a real risk that some sites may have been overlooked or deprioritised. The fact that exploitation is already underway means this is not a theoretical risk but an active threat. WordPress sites are often managed outside traditional IT oversight, with updates handled by marketing teams, external agencies or freelance developers. This fragmented ownership model creates gaps in patching discipline, particularly for urgent security updates. The consequences of compromise can be significant, ranging from defacement and data theft to the site being used as a platform for further attacks, malware distribution or phishing campaigns. For customer-facing sites, compromise can also result in reputational damage, regulatory scrutiny and loss of trust.
UK organisations should immediately verify that all WordPress instances, including those managed by third parties or hosted externally, have been updated to the latest patched version. This includes not just primary corporate websites but also microsites, campaign landing pages, regional sites, archived content and any other WordPress installations that may still be accessible on the internet. Organisations should review who holds responsibility for patching across their web estate, particularly where sites are managed by agencies, freelancers or departments outside IT, and ensure there is a clear process for urgent security updates to be applied consistently and quickly. Consider implementing a centralised inventory of all WordPress sites, who manages them, and when they were last updated. Where patching responsibility sits outside IT, ensure there is a clear escalation path for critical security updates and that non-technical teams understand the urgency of applying patches when exploitation is active. Organisations should also review whether WordPress sites are included in vulnerability scanning, patch management processes and incident response plans, and whether there is monitoring in place to detect signs of compromise such as unexpected file changes, new user accounts or unusual outbound traffic.
Source: TechCrunch