A flaw in WordPress itself lets a criminal take over the whole site with no login and nothing for you to click. Two out of five websites run on it. Here is why this is your problem, and how to know if your door is already closed.
See Where Your Business Stands →
A plain-English computer security scan. No card needed to see your results.
The problem: A WordPress security vulnerability just went public, and it is the bad kind. Not a plug-in, not a theme, the core software the whole site is built on. A criminal can take over the entire site with no password and no warning. There is a fix, but a fix only works if somebody you can name actually installs it.
The straight answer: “We have a website” and “somebody is keeping our website patched” are two completely different sentences. The gap between them is where this bites. Let me show you the flaw in plain English, what a hijacked site actually costs, and how to find out this week whether your door is open.
Hey folks! If your business runs on WordPress, and roughly two out of five websites in the world do, I need two minutes of your attention on this one.
Security researchers found a serious flaw in WordPress itself. Not in a plug-in you added, not in a theme you picked, but in the core software that the whole site is built on. In plain English, the flaw lets a criminal take over your entire site with no login, no password, and nothing for you to click. They do not have to trick anyone. They just walk in.
It went public on July 17. Within days, working attack tools were passing around online, and the government’s own cyber agency put it on the short list of flaws that criminals are actively using right now. That last part matters. This is not a theory. It is being used in the wild, today, against real businesses.
Now, here is the good news, and the trap hiding inside it. There is a fix. You update to the patched version and the door closes. A patch, by the way, is just a software update that fixes a security hole. The trap is the part that always gets businesses: someone actually has to install it, this week, before the crooks get to your site first. A fix nobody applies is not protection. It is a memo.
Sources: Rapid7 (CVE-2026-63030 / CVE-2026-60137), July 2026; SecurityWeek.
This one flaw will get patched. The reason I am spending a whole article on it is that it points at a blind spot most owners never had explained to them, and that blind spot is not going anywhere.
Here is the piece almost nobody tells you. The automatic updates you count on only cover a slice of what you run. Windows Update patches Windows. It does not touch WordPress, your plug-ins, your PDF reader, your remote-access tool, or the dozen other programs your business quietly depends on. Every one of those is its own door, with its own lock, that somebody has to keep patched on its own schedule. Your website is one of the biggest of those doors, and it is standing out on the public internet where every automated tool in the world can rattle the handle.
So the real problem is not this one WordPress hole. It is the quiet assumption underneath it: that because the site works, someone must be maintaining it. Working and maintained are not the same thing. A site can run perfectly for years while the software under it goes stale, and you would never know from looking at it. The criminals are not looking at the front page. They are checking the version number, and an automated tool checks thousands of sites an hour.
I have watched this exact gap take down businesses that thought they were careful. The owner is not careless. The owner just assumed “we have a website” meant “our website is handled,” because no one ever drew the line between the two. Keeping a business safe in 2026 is not a patch-it-on-a-Saturday job, and knowing your way around a computer is not the same as doing security. Those are two different trades now.
A taken-over website does not feel like a big deal until you follow the money. Let me follow it for you, because this is a business problem, not a tech one.
That is the real bill, and none of it shows up as a line item you can see coming. It shows up as a bad week, a scramble, and a stack of apologies. The whole point of keeping the door patched is that you never have to find out what is on the other side of it.
My own father fell for a phishing email. That is a fake message built to trick you into giving up a password or your money. More than three decades in this field, and it still reached the person I most wanted to protect. Scammers got into his computer from far away and started hunting for his financial papers. My step-mother noticed something was wrong and called me. I stopped them before they reached his bank logins. We were lucky. We caught it in time. A day slower and it would have been a very different phone call.
That is what an unwatched door feels like when it is your family, and it is why I do this the way I do. More than 35 years at this, since 1991. FBI InfraGard trainer. Not one client I manage has ever been hit by ransomware, which is software that locks up your files and holds them for money. That is not luck. It is a real person watching the doors, all of them, instead of assuming a tool has it covered.
Maybe. But when did you last confirm it, and can you name who is responsible for the update that closes this specific hole? A web designer builds the site. That is a different job from watching it every week and patching it fast when a flaw like this drops. And most web hosts secure their own servers, not the WordPress software and plug-ins sitting on top, which is exactly where this flaw lives. The space between “someone set it up” and “someone is watching it” is where the break-in happens.
So the honest question is not “do I have a web guy and a host.” It is “can I name the person who keeps every part of my site patched, and be sure they already closed this hole?” If there is even a pause before you answer, that pause is the open door.
Let me ask you a few plain questions, and just answer them in your head. You did not go into business to babysit software versions, right? You figured that when the site was built, the safety came with it. You are a careful owner, the kind who reads a warning like this all the way down instead of clicking away. And if you are honest, you are not actually sure who patched your site last, or when. Sit with those last two together, because they are both true, and that is an uncomfortable place to be.
That discomfort does not mean you dropped the ball. It is the gap between the careful owner you are and a door that quietly went unwatched while you were running the business. That gap is not a knock on you. It opened because nobody ever drew the line between having a website and maintaining one, and because the criminals got faster while the assumptions stayed the same.
Here is the thing about that gap. You close it one of two ways. You can tell yourself the web guy has probably got it, and carry that little question into the next headline like this one. Or you can take a few minutes, find out exactly where your site and the rest of your software stand, and put it to bed. One of those roads ends the worry. The other just reschedules it. Acting is not the risky move here. Acting is what makes the worry stop.
One flaw today, a different one next month. The fix is not chasing each headline. It is having someone who watches every door, your website included, and closes the dangerous ones fast. You do not have to do it alone.
Book a call, on us. We scan your business and fix the three things most likely to hurt you right now. You will not pay a dime, and you decide what happens next.
Not one client we manage has ever been hit by ransomware. That is not luck. That is someone actually watching the doors.
You run your business. We keep it running.
Book My Call →
A few minutes with a real person, straight talk on where your business stands. No pressure.
Want this kind of plain-English security news every week? Sign up for Craig’s Insider Notes at CraigPeterson.com.
#WordPressSecurity #SmallBusinessCybersecurity #Patching #ForwardToSafety
Join thousands of security professionals who receive Craig Peterson's Insider Show Notes and cybersecurity updates.
Join 10,000+ cybersecurity professionals