On Friday 25 September the Dutch National Cyber Security Centre warned of active exploitation of a critical vulnerability in the WordPress core. The flaw, CVE-2026-87902, is a path traversal issue that lets an attacker run their own code on the web server. For a website that is the worst case: whoever can execute code can alter the site, take data out, or use the server as a stepping stone. More than forty per cent of all websites run on WordPress, so the reach is considerable.
What is happening
The flaw is not in a plugin or a theme but in WordPress itself. Any installation that has not been updated is in principle exposed. The NCSC speaks of active exploitation: attackers are already at work. The fix is available in WordPress 7.1.2, and separate security updates have been released for older supported branches. The NCSC advisory leaves little room for interpretation: update, and do it now.
A second WordPress problem surfaced the same day. The widely used Elementor builder contained a flaw that lets an attacker create their own administrator account as soon as a logged-in administrator clicks a link sent to them. That has been fixed in version 4.3.2. The two issues are unrelated, but the lesson is the same: a website is not a brochure that stands still, it is software that needs maintenance.
Why this hits smaller organisations harder
In many organisations the website is the one system without a clear owner. Laptops are managed and the mail environment is monitored, but the site sits with a hosting provider, was delivered by an agency at some point, and falls between the cracks. That is precisely what makes it attractive. A hijacked company site gets used to distribute malware or to host phishing pages under your own domain name, which damages your email reputation and your customers' trust.
Then there is the GDPR. If your site processes contact forms or job applications, unauthorised access is a potential personal data breach that must be reported to the Dutch Data Protection Authority within 72 hours. Without logging you cannot tell whether anything happened.
What to do this week
- Establish which WordPress version your site runs and update to 7.1.2 or the security release for your branch.
- Enable automatic core updates; the risk of delay outweighs the risk of an automatic update.
- Update plugins and themes, Elementor to 4.3.2, and remove what you no longer use.
- Reduce administrator accounts and enable two-factor authentication on the ones that remain.
- Check that a backup exists which you can actually restore, and keep it off the web server.
- Review the logs for file changes you cannot account for.
What we do about it
For customers with managed workplaces and infrastructure we follow advisories from the NCSC and from vendors every day, and assess for each one whether it touches something running in your environment. Where exploitation is active we do not wait for the next maintenance window; we act straight away and tell you what was done. If your website sits outside those arrangements, this is the moment to record who is responsible for updates and who acts on them at the weekend. That question is often worth more than the update itself.
If you are not certain that your website and the rest of your environment were patched this week, we are happy to look with you. Book a conversation with an engineer and we will go through your situation in concrete terms.
Sources
- NCSC meldt actief misbruik van kritiek WordPress-lek: 'Update nu' — Security.NL (2026-09-25)
- Elementor WordPress flaw lets attackers create admin accounts — BleepingComputer (2026-09-25)
Read also
Citrix NetScaler exploited before a patch existed
Ready to run worry-free?
Book a no-obligation introduction. We map your IT and security and show where the difference lies.
Book a call →
