A serious WordPress security flaw has just been discovered.
Here’s what it means for your business, in plain English.
A critical security problem has just been found in WordPress, the software that powers roughly 4 in 10 websites on the internet. If your business website runs on WordPress, and there’s a good chance it does, attackers could take full control of it without needing a password, a login, or anyone at your company clicking on anything dodgy.
The good news? There’s already a fix. Updating your website closes the door completely. The bad news? A lot of small business websites don’t get updated regularly, and many owners don’t even know who’s responsible for doing it.
If that sounds like you, this article is worth 5 minutes of your time.
First things first: is your website actually WordPress?
You’d be surprised how many business owners aren’t sure. Here are a few quick clues:
- Your website was built by a freelancer, marketing agency or web designer in the last 10 years
- You log in somewhere to edit your own pages or blog posts
- Your web address ends with something like /wp-admin when you log in
- Your designer has ever mentioned “plugins”, “themes” or “the dashboard”
If any of that rings a bell, you’re almost certainly on WordPress. And if you genuinely have no idea, that’s a warning sign in itself. Someone should know, and you should know who that someone is.
What’s actually happened?
Security researchers have discovered a flaw in the core of WordPress itself. It’s been given the reference CVE-2026-63030, and nicknamed “wp2shell” in the security world.
In practical terms:
- Attackers don’t need a password. They don’t need to trick an employee. They don’t need to guess your login. They just need to find your website online, which, since your website is designed to be found, is trivially easy.
- They can then take full control. That means stealing data, changing your pages, adding hidden links, redirecting visitors to scam sites, or using your site as a launchpad to attack others.
- Standard websites are affected. You don’t need any unusual plugins or a fancy setup to be vulnerable. A bog-standard WordPress site is enough.
The flaw affects WordPress versions 6.9.0 through 6.9.4, and 7.0.0 through 7.0.1. It’s fixed in 6.9.5, 7.0.2 and 7.1 Beta 2.
Why should you care?
Because your website is often the first thing a potential customer sees. A hacked site can quietly cause a lot of damage before you even notice:
- Lost sales. Customers who land on a broken or dodgy-looking site leave and don’t come back.
- Lost trust. Google will flag hacked websites with a big red warning. That warning lives in people’s memory.
- Blacklisting. Search engines can remove you from their results, and it can take weeks to recover your rankings.
- Data protection headaches. If customer data is stolen, you may have legal reporting obligations under UK GDPR.
- Ransom demands. Some attackers lock you out and demand money to give your website back.
- Reputational damage. “Have you seen what’s on their website?” is a conversation you never want a customer to have.
For a small business, a hacked website isn’t just an IT problem. It’s a sales problem, a marketing problem and a legal problem all rolled into one.
The bit that makes this one worse than usual
Two things make this vulnerability particularly worrying:
- No user interaction needed. Normally you hear advice like “don’t click suspicious links” or “don’t open dodgy attachments”. This one bypasses all of that. Your team could do everything right and still be affected.
- A public how-to guide is expected soon. Researchers reckon that with modern AI tools, it won’t take long for criminals to publish step-by-step instructions on how to exploit this. When that happens, automated attacks will scan the whole internet looking for unpatched sites. Yours could be one of them.
In other words: the window to sort this out is now, not next month.
What to do now
You don’t need to be technical to take action. Here’s a simple checklist:
1. Find out who looks after your website. Is it an in-house person, a freelancer, a marketing agency, or your web designer from a few years ago? If nobody springs to mind, that’s your first job. Someone has to own it.
2. Ask them one question. “Is our WordPress site running version 6.9.5 or 7.0.2, or newer?” If the answer is yes, you’re safe from this particular issue. If the answer is no, or “I’ll get back to you”, push for it to be done today.
3. Check auto-updates are actually working. WordPress can update itself in the background, but only if it’s set up to. Ask your web person to confirm auto-updates are enabled and have run successfully. Don’t just assume.
4. Update your plugins and themes too. This particular flaw is in WordPress itself, but plugins and themes are the other common way sites get hacked. A quick health check now is worth doing.
5. Check for anything odd. Have a click around your own site. Any new pages you don’t recognise? Any strange redirects? Any admin users you don’t know? These are red flags.
6. Don’t forget the “other” sites. Many businesses have a main site plus a few extras: landing pages, a blog, an old campaign site, an event microsite. Every WordPress site you own needs the same treatment. Attackers don’t care which one is your priority.
What to do if nobody is looking after your website
This is more common than you’d think, and it’s exactly the situation that puts small businesses at risk. Websites are often set up once, then left alone for years until something breaks. That’s fine, right up until it isn’t.
If you’re in that boat, you have three sensible options:
- Ask your original web designer if they offer a maintenance plan. Many do, and it’s usually cheaper than you’d expect.
- Bring in an IT partner (like us) to look after it as part of your wider IT and cyber security cover.
Whichever you choose, the key point is: someone needs to be responsible for keeping your website up to date, all the time, not just when there’s a headline.
How HJS Technology can help
We look after IT and cyber security for small and mid-sized businesses across Hampshire and the South. If you’re not sure whether your website is safe, we can:
- Check what version of WordPress you’re running
- Patch it to the latest secure version
- Review your hosting, backups and login security
- Set up ongoing monitoring so the next critical flaw is dealt with before it becomes your problem
- Include your website in your wider cyber security plan alongside your emails, devices and cloud services
No jargon, no hard sell, just a straight answer on whether you’re exposed and what to do about it.
Ready to check?
📞 Call us on 023 8038 6586 💬 Email info@hjstechnology.co.uk 🌐 Or visit hjstechnology.co.uk and book a quick chat
We’ll take a look, tell you where you stand, and put your mind at ease. If everything’s fine, you’ll know. If it isn’t, we’ll fix it.
Your website works hard for your business. Let’s make sure it isn’t working for anyone else.
Don’t forget to follow us on LinkedIn for more news and advice.