Skip to main content
    Millions of WordPress Websites Under Attack: What Website Owners Need to Do Now
    Cybersecurity
    Breaking
    2 min read

    Millions of WordPress Websites Under Attack: What Website Owners Need to Do Now

    Hackers are exploiting security flaws in WordPress that could let them take over websites. If you run a WordPress site, you need to update immediately.

    Source

    TechCrunch Security

    Original headline: Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk

    Plain-English summary by GetCyberRight. Read the full report at the source above.

    Published Monday, July 20, 2026Updated Tuesday, July 21, 20262 min read
    Share:

    Two serious security problems were recently discovered in WordPress, the software that powers millions of websites around the world. Hackers have already started exploiting these flaws to take over websites remotely.

    When hackers take control of a website, they can steal information, spread malware to visitors, or use the site for illegal activities. This affects anyone who runs a website using WordPress. This includes small business owners, bloggers, teachers running classroom sites, and anyone else with a WordPress site. If hackers take over your site, they could access customer information, change your content, or make your site dangerous for visitors. Your website could also be taken down or used to attack other sites.

    Stay one step ahead of scammers

    Weekly cybersecurity briefings for families. No spam, just the threats that matter and what to do about them.

    If you have a WordPress website, you must take action immediately.

    1. Log into your WordPress dashboard right away.
    2. Go to the Updates section and install all available updates for WordPress itself and any plugins you use.
    3. If you are not sure how to update your site, contact your web hosting company or the person who built your website and ask them to update it immediately.
    4. After updating, change your WordPress admin password to a strong, unique password.
    5. Enable two factor authentication on your WordPress account if this option is available. Keeping your website software updated is one of the most important things you can do for security. Set a reminder to check for WordPress updates every week. Consider turning on automatic updates if your hosting provider offers this option. If managing updates feels overwhelming, hire a professional to maintain your site or switch to a managed WordPress hosting service that handles updates for you. A hacked website can damage your reputation and put your visitors at risk, so keeping it updated is worth the time and effort.

    Protect Yourself

    Stay one step ahead with our free family cybersecurity tools. Check links, scan for breached accounts, and get personalized risk assessments.

    Found this useful?

    Share it with someone who could use a heads-up.

    Share:

    Curated from trusted cybersecurity sources by GetCyberRight

    Source: TechCrunch Security

    Discussion

    0

    Sign in to join the discussion.

    Stay ahead of cyber threats

    Get our free weekly digest. Real threats, plain language, what to do about them. No spam, ever.