RESOURCES / WEB DEVELOPMENT

Two WordPress Security Fixes in a Week: What Business Owners Should Do

·By Ven Agency
Two WordPress Security Fixes in a Week: What Business Owners Should Do

If your website runs on WordPress, September has been a busy month for security. WordPress released two security updates in six days, and one of them fixes a critical flaw. Attackers have also been going after Elementor Pro, a popular page-builder plugin. None of this is a reason to panic, but it is a good reason to spend ten minutes checking your site.

Here's what happened, what it means for a business website, and what to do next.

Two security releases in six days

On 17 September, WordPress released version 7.1.1. It fixes 11 security vulnerabilities, along with a batch of general bug fixes. One of those vulnerabilities, nicknamed Click2Shell, now has a public proof-of-concept exploit. That means working attack code is out in the open, which makes it easier for someone to try it against sites that haven't updated.

Five days later, on 22 September, WordPress released version 7.1.2. It fixes a flaw WordPress rates as critical. Someone who isn't logged in can use it to make a site load a PHP file it shouldn't, and on some server and theme setups, that can let them run their own code on the site. It affects every version from 4.7 up to 7.1.1. As of 22 September, no attacks using it had been reported.

Both are security releases, so sites with automatic background updates switched on should install them without anyone lifting a finger. WordPress turns these on by default for security releases, but not every site keeps them on. Some hosts, developers and plugins switch them off.

The Elementor Pro flaw

Separately, attackers have been exploiting a flaw in Elementor Pro, a paid plugin many businesses use to build pages and forms. It affects Elementor Pro 4.2.1 and earlier, and was fixed in version 4.2.2 on 19 August.

It only affects sites with a published Elementor Pro form that includes a file upload field. Where that's the case, an attacker doesn't need to log in. Security firm Wordfence blocked more than 190,000 attempts to exploit it in the five days after the fix came out. Where attacks succeed, attackers have been planting a hidden file, known as a webshell, that lets them run commands on the server and take over the site.

Doesn't WordPress check plugins now?

It does, for some of them. WordPress.org now holds every plugin release in its official directory for six hours while the code is scanned by several AI models and Jetpack Scan. Since September, releases that look high risk are blocked automatically. That's a genuine improvement for plugins you install from the WordPress.org directory.

It doesn't cover premium plugins you buy and download from somewhere else, and Elementor Pro is one of those. The same goes for many paid themes and plugins. For those, updates still depend on you, your developer or whoever maintains your site.

What to do now

  • Check your WordPress version. In your dashboard, open Updates. You want 7.1.2 or later.
  • Update Elementor Pro if you use it. Version 4.2.2 or later fixes the flaw. It matters most if any of your forms let visitors upload files.
  • Update your other plugins and themes, and delete any you no longer use. Deactivated plugins still sit on your server.
  • Take a backup first, so you can roll back if an update causes a problem.
  • Check that automatic security updates are on, or that someone is responsible for applying them quickly.
  • Look for anything unfamiliar, such as admin users you don't recognise or files you didn't add. If you find something, get help before you change anything else.

If Ven looks after your website

If your site is on a Ven maintenance plan, keeping WordPress, your theme and your plugins up to date is part of that plan, so there's nothing you need to do here. Hosting and maintenance are separate services, so if you're not sure whether your site is covered, ask us to check.

From Ven

Not on a maintenance plan?

We keep WordPress, themes and plugins updated, so security fixes like these are handled for you.

Ask about a plan

The bottom line

WordPress is still a solid platform for business websites, and these releases show the system working as it should: flaws found, fixed and published quickly. The risk sits with sites that don't get updated. A few minutes of checking now, or a plan that does it for you, costs far less than cleaning up a hacked site.

Related reading: why your business can't afford free web hosting.

Also this week: Search Console's new AI report and Australia's plan to let people switch off the algorithm.

Sources

Ven Agency

The Ven Agency team specialises in web design, SEO, and digital marketing for Australian businesses.

Related Services