400,000 websites were recently discovered to be vulnerable to a complete account takeover — meaning an attacker could log in as the site administrator without a username or a password.
No hacking. No guessing. Just walk straight in.
The scary part? Most of those website owners had absolutely no idea.
What Happened?
A critical security flaw was found in a popular WordPress plugin used by hundreds of thousands of websites worldwide. The flaw was rated 9.8 out of 10 on the severity scale — as close to “worst possible” as it gets.
The vulnerability allowed anyone on the internet to completely bypass the login system and gain full administrator access to affected websites. From there, an attacker could lock out the real owner, steal data, deface the site, or use it to attack others.
A fix was released — but here’s the catch: many of the affected websites never received an update notification. The plugin shipped in multiple versions, and the alerts only reached some of them. Thousands of site owners were left exposed without knowing it.
You can read the full technical breakdown here: Patchstack Security Advisory →
Why Are You Reading This?
Because there’s a good chance your website is in the same position as those 400,000.
Not because of this specific plugin — but because of the situation: a WordPress website, running software you don’t fully know about, managed by someone you haven’t spoken to in a while (or no one at all).
This is the reality for most small business websites in Australia. The site was built, handed over, and quietly forgotten about from a maintenance perspective. It looks fine. It works. So why would you think about it?
Three Questions Worth Asking Yourself Right Now
1. What is my website running on?
If you don’t know, you’re not alone — but you should find out. WordPress powers over 40% of all websites in the world. If yours is one of them, it needs regular attention.
2. Who is responsible for keeping it updated?
Your web developer? Your IT provider? You? If the answer is “I assume someone is,” that’s not good enough. Get it in writing, or find someone who will own it.
3. When was it last actually checked?
Not “when did someone last look at the homepage.” When was the software last updated? When were security vulnerabilities last reviewed? If you don’t know the answer — that’s the answer.
Your Website Is a Front Door to Your Business
A compromised website isn’t just an inconvenience. It can mean:
- Google blacklisting your site — with a visible “This site may be harmful” warning that kills your traffic overnight
- Customer data exposed — contact form submissions, enquiries, anything stored in your database
- Your domain used for spam — attackers use hacked sites to send phishing emails, which gets your domain blacklisted
- Costly recovery — cleaning up a compromised WordPress site typically runs $500–$2,000+, not counting lost business
And in most cases, owners find out weeks later. By then, the damage is done.
We’ll Check Your Website — Free
ESI IT is offering a free manual security check for small business websites.
Simply head to our contact page, and in the message field write: “Please scan my website” along with your website address. We’ll review it and email you a plain-English summary of what we find — what platform it’s running on, whether the software is up to date, and whether there are any obvious vulnerabilities.
No automated scan. No sales pressure. A real review, by a real person, straight to your inbox.
👉 Request your free website check →
Want Someone to Just Handle It?
That’s exactly what our WordPress Website Care service does.
We take care of the updates, run regular security checks, and send you a monthly report. It runs quietly in the background — and you only notice it when something doesn’t go wrong.
If you’ve been meaning to sort out who’s actually looking after your website, this is the easy answer.
