WordPress security alerts can sound worrying, particularly when your website is busy bringing in enquiries, taking orders or supporting customers. Recent vulnerabilities are a useful reminder that keeping a website secure is an ongoing job, even when everything looks fine on the surface.
At Platform81, we help take that job off your hands through regular maintenance, daily vulnerability scans and practical support from our web development team. Here’s what the recent alerts mean and how we help.
What has been found in WordPress
In July 2026, two vulnerabilities were disclosed in WordPress core, the underlying software that runs a WordPress website. Together, they became known as “wp2shell”.
One involved the way WordPress handles certain incoming requests. The other affected how it processes information used in database queries. Combined, these weaknesses could allow an attacker to run malicious code on an affected website without logging in. WordPress released fixes, including version 7.0.2. WordPress security advisory.
NHS England subsequently issued an alert reporting exploitation of the vulnerabilities. This made prompt updates particularly important for affected websites. Having vulnerable software installed does not automatically mean a website has been hacked, but it does mean there is a weakness that needs attention. NHS England alert.
How vulnerabilities slip through
WordPress core and plugins are software, and software can contain flaws that nobody has identified yet. A release can work exactly as expected during everyday use while still containing a weakness that only becomes apparent when someone tries an unusual combination of actions.
That means even a well-maintained website can be running the latest available version of a plugin when a new vulnerability is discovered. Once the developer releases a security fix, that update needs to be applied to the website.
Plugins deserve the same attention as WordPress itself. Each one adds code and functionality, whether that’s a contact form, an online shop or a booking system. Keeping the core software updated while leaving plugins untouched can still leave a website exposed.
AI is helping attackers move faster
The rapid development of AI is also making it easier for attackers to analyse code, identify potential weaknesses and develop attacks. This affects WordPress alongside other website platforms. The UK’s National Cyber Security Centre warns that AI is shortening the time between a vulnerability being discovered and attackers exploiting it. That gives website owners less time to respond. NCSC guidance.
How Platform81 helps
Our monthly website support packages combine routine maintenance with ongoing monitoring, so looking after your website continues between scheduled updates.
Each month, our skilled web developers carry out WordPress and plugin updates, alongside checks and testing. They apply the updates, test the website and test again to check that everything continues to work as expected.
That human involvement matters. An update can affect how different parts of a website work together. A successful installation message alone doesn’t tell you whether a form still submits correctly or an important customer journey still works. Our maintenance process includes developers checking the result.
Support clients also receive ongoing monitoring, with daily scans that alert us to known vulnerabilities affecting their websites. These checks help us identify issues between monthly maintenance visits.
When a medium, high or critical risk vulnerability is flagged, we begin addressing it straight away. Where a patch is available, we apply and test it. If a fix hasn’t been released, we assess the appropriate steps to reduce exposure while a permanent solution is arranged.
If malware is detected, we handle the investigation, clean-up and necessary patching. Removing malicious files and addressing the weakness that allowed them in are both part of getting a website back into a healthy state.
Already a Platform81 support client?
If you’re already on one of our website support packages, this service is already running for you. Your routine updates, testing, ongoing monitoring and daily vulnerability scans are part of the support we provide, and we act on flagged security issues as described above. There’s no need to book a separate maintenance visit when you see a security headline; we’ll contact you if anything needs your input.
If you’re not currently on a support package, speak to our team about website maintenance and we’ll help you find the right level of support for your business.