Let’s Talk Security!!

Mid-Year Website Security Checkup: Critical Vulnerabilities and how to protect your websites from them.

Whether you run a personal blog, an online store, or a business website, security should always be part of your regular website maintenance. 

Over the past couple of months, several high-profile vulnerabilities have affected popular web applications and server software. While security issues are constantly discovered across the internet, the good news is that most successful attacks can be prevented with a few simple maintenance habits. 

Let’s go over the recent vulnerabilities and walk through practical steps any site owner can do to keep their site up to date with the latest best practices in the industry.  

What is a CVE?

CVE stands for Common Vulnerabilities and Exposures. These threats are detected and categorized by an identifying number to keep track of publicly known software security flaws.  
Usually, when developers discover a vulnerability, they release a security update that fixes it as quickly as they can. The biggest risk isn’t that vulnerabilities exist—it’s when websites continue running outdated software after a fix has already been released.

Recent Security Highlights 

Several important vulnerabilities were disclosed recently on widely used content management systems that are used by millions of people everyday. A content management system, or CMS, is software that lets users create, edit, and manage website content without needing to write all the code themselves. Today, I will discuss a few of the most relevant ones related to our products that we offer and what you can do to avoid being affected by these latest discoveries.  

WordPress: On July 17, 2026, WordPress released a security update addressing two serious vulnerabilities in WordPress Core: CVE-2026-60137 and CVE-2026-63030. These issues affected the core WordPress software and involved weaknesses in how certain requests and database operations were handled. If exploited, attackers could potentially gain unauthorized access and take control of a vulnerable website. Website owners running WordPress 6.8.x should update to WordPress 6.8.6, users on the 6.9.x branch should update to 6.9.5, and users on WordPress 7.0.x should update to 7.0.2 or later to apply the security fixes. 

Joomla: Joomla recently released security updates addressing vulnerabilities in Joomla Core. One of the latest issues, tracked as CVE-2026-48958, involved incorrect access controls within Joomla web service endpoints. The vulnerability could allow unauthorized users to perform actions they should not have permission to complete. The issue affected Joomla versions 4.0.0 through 5.4.6 and 6.0.0 through 6.1.1. Joomla administrators should update to Joomla 5.4.7 or Joomla 6.1.2 to ensure these security protections are applied. 

 
We always encourage and suggest that website owners keep their websites, themes, plugins, and extensions up to date as often as possible to prevent being affected by exploits like these. 

Remember: An outdated plugin is often a bigger security risk than the server itself.

How to update WordPress and Joomla

Luckily these are very popular CMS so there is a plethora of videos, forums, and groups online that provide instructions on how to update your site but here is the instructions for each: 
 
WordPress 
https://developer.wordpress.org/advanced-administration/upgrade/upgrading/ 
 
Joomla  
https://guide.joomla.org/user-manual/migration/migration-version-update

The 4 Biggest Ways Websites Get Compromised 

Most hacked websites share one of these common causes no matter what type of code, content management systems, or web application firewalls they may use. 

1. Outdated Website Software 
 
WordPress, Joomla, Drupal, ColdFusion applications, PHP-based websites, and other web platforms regularly release security updates. 

As discussed earlier regarding the latest vulnerabilities, running outdated software significantly increases the risk of attackers exploiting known security flaws. 

Be sure to keep the following up to date: 

  • Core CMS or application software 
  • PHP version 
  • ColdFusion versions or syntax   
  • Plugins 
  • Themes 
  • Templates 
  • Extensions 

2. Weak Passwords 

Strong passwords remain one of the easiest ways to improve security. Use unique passwords for crucial access points to your site like: 

  • cPanel  
  • WordPress /Joomla Administrator  
  • FTP/SFTP  
  • SSH  
  • Email accounts  
  • Database users  

Consider using a reputable password manager so you don’t have to remember them all and you can make them more complex. Also, rotating them as often as you are able to is advised.  

3. Old Plugins and Extensions 

Many website compromises originate from third-party plugins rather than the CMS itself. 
Ask yourself: 

  • Do I still use this plugin?  
  • Is it still supported?  
  • Has it been updated recently?  

If the answer is no to any of these, consider removing it. 

4. Backup Availability 

Backups won’t prevent an attack—but they can dramatically reduce downtime if something goes wrong. If your website becomes corrupted, infected, or accidentally deleted, a recent backup can save hours—or days—of work.

Hostek’s Backup procedure and Expectations

Here at Hostek we provide a courtesy backup of your site email, web, and database files. These backups are collected every night and retained for the specified days depending on the hosting plan. Shared hosting plans receive 14 days and cloud customers get to choose up to 30 days when selecting their product for purchase.   
 
Although we provide these backups, they are not guaranteed. In rare cases backup files can be corrupted or may fail to be collected. It is highly encouraged that our users create their own backup schedule that works for them. Also, it is helpful to collect backups before any major updates to the site. That way, you can easily revert if something goes wrong.

Need a simple solution to make Backup scheduling easier?

If you want a much more simple solution than you may be interested in CodeGuard. This is  a fully automated website backup service that gives you complete protection against data loss and malware found on your site. This is perfect for users that utilize common CMS like WordPress, Joomla, or Drupal . And if anything ever goes wrong — a bad update, a hack, an accidental deletion — you can restore your whole site to any previous day yourself, in one click, without waiting on a ticket. This helpful solution includes awesome features like: 
 
File Change Monitoring – Get notified by email anytime something changes within the source code of your site. 

One-Click Restores –A simple restore process makes it easy to rollback a single file or your entire website to a previous version. 

Staging of Restores- Quickly test any backed up site with simple and automated staging prior to restore. 
 
The way it works is it scans your site for malware, emails you if anything changes, and — if you’re on WordPress — it can even handle your core, plugin, and theme updates automatically, checking the site still works and rolling back on its own if an update breaks something. This is not a preventative security product — it detects malware already present and lets the user recover, but it does not block attacks in the first place.  
 
If you want to stop hacks before they happen, then it is a Web Application Firewall service you want to pair with this type of service. Here at Hostek we offer Sucuri WAF — the two complement each other well.  
 
For more information about CodeGuard you can visit: 
 https://cp.hostek.co.uk/store/codeguard 
https://cp.hostek.com/store/codeguard 
 
Reach out to Hostek Support today if you are interested in CodeGuard. We can get this added in minutes and you can enjoy hands free automated daily backups for your accounts hosted domain!  

That’s all for now

Thanks again for stopping by and taking the time to familiarize yourself with the latest best security practices. Websites are a little like houseplants: ignore them for too long and things start getting weird. A forgotten update here, an outdated plugin there, and suddenly your peaceful little corner of the internet has become a playground for troublemakers. So water your website, give it some love, back it up before the storms arrive, and keep those updates rolling. Your future self (and your visitors) will thank you.  
 
Until next time! 
Joke of the month-  
What is a hacker’s favorite sport? Phishing!