Over the summer, two serious flaws were found in WordPress — the software behind more than four in ten websites, and very possibly yours.

Both let attackers take control of the servers behind ordinary business websites. Neither was the site owner's fault. Most people missed them entirely, because the fixes happened quietly in the background.

The useful question isn't whether you were affected. It's whether you'd know either way.

Four questions

  1. When was your website software last updated?
  2. Does it update itself automatically?
  3. If someone got in during July, would you know?
  4. How many websites does your business actually own?

That last one catches almost everyone — an old campaign site, a test version someone set up, a page a former employee built. You can't protect what you've forgotten you own, and the automated attacks scanning the internet all day don't care that you'd forgotten it.

The bit that surprises people

Updating fixes the flaw. It does not remove anyone who already got in beforehand.

The summer's first problem was being actively exploited within days, with attackers leaving themselves a hidden back door. Sites that updated afterwards closed the front door with someone already inside.

So "we're up to date" is a good answer to the wrong question.

Why this keeps happening

Both flaws were found using artificial intelligence. In one case the researchers said their system found it and worked out how to exploit it in about four days — in code that had been sitting in WordPress unnoticed since 2016.

Both were reported properly and fixed. But the same tools are available to people with worse intentions, and the gap between a flaw being found and being exploited is closing fast. There will be more, probably before Christmas. Normally they arrive at late on a Friday afternoon!

What actually helps

  • Leave automatic updates on. If updating breaks your site, that's a problem with your site, not a reason to stop.
  • Write down every website you own, including the forgotten ones, and retire what you don't need.
  • Actually test your backups. Plenty don't work, and people find out on the worst possible day.
  • And have someone watching — not once a year. These flaws arrived without warning and were exploited within days.

Where we come in

That last point is what we do. We keep an eye on our clients' systems, flag them when a new flaw puts them at risk, and spot the things that slip through. When something happens they get a phone call from a person. We're CREST accredited, based in Albrighton, and you deal directly with the person doing the work.

If you're not sure whether your website was caught up in either of these, we'll take a look and tell you. Email us at This email address is being protected from spambots. You need JavaScript enabled to view it. with your website details for a free, no obligation check — and if everything's fine, that's what we'll say.