In recent weeks, there has been a lot of news about security vulnerabilities in WordPress and popular plugins. Some of them could lead to an administrator account takeover, malicious code running on the server, or leaked email-sending credentials. These are serious problems that are often difficult and costly to fix. If your website runs on WordPress, it is worth knowing what happened and what to check to reduce the risk.
A website can work and still be vulnerable
WordPress is convenient, popular and can still be a good choice for many companies. The problem begins when, after launch, no one regularly checks updates, plugins, administrator accounts and backups.
On the surface, everything may look normal. The website loads, the form works, the blog can be edited and the admin panel opens without issues. Underneath, however, there may be outdated add-ons, vulnerable login mechanisms or features that attackers are already trying to exploit.
Recent cases described by security-focused publications such as Niebezpiecznik and Sekurak show that the risk is not limited to obscure plugins. Sometimes the issue appears in a popular add-on, and sometimes in WordPress itself.
What happened in recent weeks?
The reported cases involved several different attack scenarios. Each one looks different, but they share one simple point: a neglected or outdated website can become an easy target. The key examples in brief:
A vulnerability was found in WordPress itself where a logged-in administrator clicking a crafted link could give an attacker a path to take over the website. This is especially dangerous because many people work all day in the same browser where they are logged into the WordPress admin panel.
Other WordPress bugs could allow an external person to run their own code on the website server. That means a risk of replacing content, adding malicious files or using the website for further attacks.
A vulnerability in the Everest Forms Pro plugin could turn a normal contact form into a backdoor to the website. Attackers could use the form not to send a message, but to perform actions on the server, including creating administrator accounts.
A bug in Gravity SMTP could reveal data needed to send emails from the website. Such information can be used for spam, phishing or impersonating the company, while also harming the domain’s reputation.
Vulnerabilities in Kirki and Burst Statistics could lead to administrator account takeover without knowing the password.
These are not minor cosmetic bugs. We are talking about situations that can end with website takeover, changed content, spam being sent, lost form enquiries or a data leak. Let’s look at them more closely.
A vulnerability in WordPress itself: when exploiting the administrator is enough
One of the reported attacks, called XSS2Shell, affected WordPress itself. It started with the login form. In a specific situation, the system could misinterpret the data entered as the login, opening the way for a further attack.
The full scenario required a person logged into the administrator panel to click a prepared link. That may sound easy to dismiss, but in everyday work this condition is not abstract at all. Many people stay logged into WordPress throughout the day and use the same browser for email, communicators and opening work-related links.
If such an attack succeeds, an external person may gain access to administrative functions, add a malicious plugin and, in the worst case, run their own code on the server.
One more detail is worth noting: according to the reported information, this attack chain was found by AI tools. It is a signal that weak points in popular systems can now be discovered faster and at a larger scale than before.
Bugs that do not require logging in are especially dangerous
Some of the reported vulnerabilities were more serious because they did not require a WordPress account or a click from the administrator. An attacker could act from the outside if the website was using a vulnerable version of the system.
That is why updates are so important. In newer WordPress versions, such vulnerabilities are patched, but information about a vulnerability often quickly reaches people who try to exploit it on outdated websites.
One bug allowed attackers to run their own code on the server where the website was hosted. This is one of the most dangerous categories of issues because it can give criminals very broad capabilities. For a company, the effects of such an attack may include:
changed content on the website,
added malicious code,
a compromised administrator account,
access to data stored in the system,
the website being used for further attacks,
warnings from the hosting provider or search engine.
In such cases, updating WordPress as quickly as possible matters. Automatic updates help, but they should not be the only safeguard. For a company website, it is worth checking whether the fix has actually been applied.
Plugins help, but each one also increases risk
Plugins are one of WordPress’s biggest conveniences. They make it possible to quickly add a form, statistics, SEO tools, email integration or payments. The problem is that every such solution is also additional code that has to be maintained.
Recently, several reports have described attacks that used vulnerabilities in popular plugins.
One example is Everest Forms Pro, a forms plugin. It had a vulnerability that, under certain conditions, allowed malicious code to be executed on the server. Attackers could use the form not to send a message, but to run their own actions. According to Wordfence, tens of thousands of attempts to exploit this vulnerability were recorded.
Gravity SMTP, a plugin used for sending emails from a website, could reveal SMTP configuration data. Put simply: an external person could obtain information needed to send messages through the service connected to the website. Such a leak can lead to:
spam being sent,
phishing attempts,
impersonating the company,
the sending domain being blocked,
problems delivering legitimate emails to customers.
This is a good example of a situation where a website does not have to be fully taken over for the company to face a serious problem.
Administrator account takeover without a password
A separate group of issues involved the Kirki and Burst Statistics plugins. In both cases, the main risk was similar: administrator account takeover.
In Kirki, the bug concerned password reset. The mechanism checked the username, but did not properly verify whether the provided email address actually belonged to that person. An attacker could know the administrator’s login, provide their own email address and take over the account.
There was also an issue with Burst Statistics, a statistics plugin. It had a vulnerability that allowed attackers to bypass login and impersonate an administrator. Once inside the panel with such privileges, they could change content, install add-ons, create more accounts and take control of the website.
The main conclusion is simple: a strong password helps, but it is not enough if the plugin’s own mechanism is vulnerable.
What should a company using WordPress check?
Even though there has recently been a lot of information about attacks, there is no need to panic. The most important step is to review the website as soon as possible and reduce potential risk. It is worth checking in particular:
whether WordPress is up to date,
whether all plugins and themes are on the latest versions,
whether there are plugins on the website that no one uses anymore,
who has an administrator account,
whether any unknown accounts have appeared in the panel,
whether backups are current and can be restored,
whether forms, email sending and integrations work correctly,
whether the hosting provider or security tools have reported unusual activity.
With serious vulnerabilities, an update alone may not be enough. You also need to check whether someone exploited the bug earlier. New administrator accounts, unknown plugins, changed files, strange log entries and unusual email activity are especially suspicious.
WordPress needs care, not just implementation
WordPress can be a good solution for a company, but it should not be treated as a project that ends on launch day. A website works all the time: it collects enquiries, builds trust, supports sales and is often the first place where a customer interacts with the brand.
That is why it is worth taking care of it like any other important business tool. Regular updates, plugin reviews, administrator account checks and backups are much cheaper than dealing with the consequences of an attack later.
If your website runs on WordPress, we can take care of its ongoing technical maintenance. We will keep an eye on updates, plugins, security, forms and administrator accounts, making sure the website stays current, stable and as resistant as possible to similar threats. Contact us to discuss the details of working together.