
WordPress Hacked? What to Do After a Hack | Jennifer Bagley & Chris Heney
WordPress Hacked? What to Do After a Hack (and Why Updates Aren't Enough) What would you do if you learned your website has been hacking your own customers? That's not a hypothetical. In this emergency livestream of the Catalyst for the Trades podcast, host Jennifer Bagley (owner of CI Web Group) sits down with CI Web Group CTO Chris Heney after a wave of hacked WordPress sites hit home-service companies in a single week. What follows is a plain-English breakdown of what's being exploited right now, how the attacks actually work, and the uncomfortable truth about what it takes to recover after a hack. The CVE wave hitting WordPress right now CVE stands for Common Vulnerability and Exposure: publicly cataloged hacks, and for WordPress they surface nearly every day. In the week of this recording, the hit list included the Divi and Avada themes and the Gravity Forms, WP Bakery, and Contact Form 7 plugins. Jennifer's estimate: 95% of trades websites are running Contact Form 7 or Gravity Forms right now, sitting in a vulnerable state. The scariest single item: a GDPR cookie-consent plugin (the little "accept or decline" popup that keeps you compliant with privacy laws) rated 10/10 severity for arbitrary file upload, with 900,000+ installs and no patch available at the time of recording. How the hacks actually work Chris walks through the attacker's playbook in plain English. Remote file inclusion (also called arbitrary file upload) lets an attacker inject a PHP shell, hosted on a site like Pastebin or GitHub, straight into your server. Privilege escalation turns any login role, even a customer or subscriber account, into an admin through WordPress's role-based access controls. Cross-site scripting (XSS) lets hackers run their own scripts on your domain, building phishing pages (a fake PayPal notice served from your URL) without touching a single file on your server. And man-in-the-middle attacks pair with keyloggers: one contractor's site was rendering as Bank of America to its visitors. Why your hacked site is everyone's problem "I don't collect data, so I'm safe" is the most dangerous sentence in this episode. Exploit frameworks aren't trying to hurt your business; your site is just the vehicle. They fingerprint each visitor's browser and serve a tailored malicious payload, quietly drafting visitor devices into botnets. A keylogger picked up from your site follows the visitor home: they log into their bank later, and the credentials get harvested. Stolen logins are brokered in underground channels and sold in bulk. If your site is compromised, your customers are exposed. After a hack: updates and new passwords are not enough One agency's response to being hacked was to change passwords and update plugins. Chris's answer: not enough. The first thing an attacker does on entry is establish a way back in. The progression taught at hacker conferences runs reconnaissance, gain access, maintain access, escalate access. Updating software closes the front door; it does nothing about the back doors already installed. When your agency holds your website hostage A trades company came to CI Web Group after their agency threatened to take the site down if they canceled. Jennifer's answer: if you're on WordPress, you don't need the agency's permission or files to recover what you own. CI Web Group has extracted sites directly with its own shell tool (published at github.com/ciwebgroup/cishell), pulling the database, themes, and plugins without the old agency's cooperation. The lesson: find out whether you actually own your website before the relationship goes bad. The January 1, 2027 line in the sand Jennifer announced it live: CI Web Group is moving every client off WordPress by January 1, 2027, and paying for the migrations itself. The replacement is the Hydra OS website platform, built on static site generation: no PHP executing in real time, pages pre-generated and served as finished HTML. The result Chris cites: perfect Lighthouse and Core Web Vitals scores the team had never achieved on any third-party infrastructure. The AI website-builder trap The episode closes with a warning for the build-it-in-AI crowd. AI site generators typically produce single-page applications (React, Next.js) where the entire page mounts via JavaScript into one empty div. To a search engine's first crawl, that page is effectively blank; indexing slows and pages can deindex. Jennifer's rule: an ugly old server-rendered site that Google can read will outperform a gorgeous AI-generated SPA every time. And "start with pretty" isn't building a product. Real development starts with discovery, buyer personas, framework, database architecture, user roles, and rules. Pretty comes last. Questions Answered in This Episode - What is a CVE, and why do new WordPress vulnerabilities surface almost daily? - Which themes and plugins were actively exploited this week? - What are remote file inclusion, privilege escalation, and cross-site scripting, in plain English? - How do hackers use a hacked contractor website to attack its visitors? - Why don't plugin updates and new passwords fix a hacked site? - What should you do if your agency threatens to take down your site? - Why is CI Web Group moving all clients off WordPress by January 1, 2027? - Why can AI-generated single-page websites destroy your Google rankings? About Jennifer Bagley Jennifer Bagley is the owner of CI Web Group and host of the Catalyst for the Trades podcast. About Chris Heney Chris Heney is the CTO of CI Web Group. Chapters 00:00 Emergency livestream: a wave of hacked WordPress sites 01:09 CI Web Group's WordPress history — early adopters in 2006, first to leave 02:34 This week's CVE wave 03:50 Live look at a hacked site: casino backlink spam 05:51 How WordPress actually works: core, themes, and plugins 09:53 "The Wall Street Journal uses WordPress" — not the way you do 12:46 Exploit frameworks, botnets, and "frags" 14:08 Divi, Avada, Gravity Forms, WP Bakery under fire 15:44 Remote file inclusion and PHP shells 17:50 A cookie-consent plugin with 900,000+ installs at 10/10 severity 21:46 When your agency holds your website hostage 23:40 Privilege escalation explained 24:58 Cross-site scripting (XSS) and phishing pages 26:26 Man-in-the-middle: the contractor site that looked like Bank of America 28:01 "I don't collect data, so I'm safe" — why that's wrong 33:02 WordPress 7.0.3 SSRF vulnerability 35:41 After a hack: why updates and new passwords aren't enough 38:12 CI Web Group's mandate: clients off WordPress by January 1, 2027 38:49 Why the Hydra OS website platform uses static site generation 41:11 The AI website-builder trap: React SPAs and deindexing risk 48:59 "Start with pretty" isn't building a product 57:20 Next up: a deep dive on Hydra's power 58:00 Close: it's your website, your business, your results Enjoyed this episode? Subscribe to "The Catalyst for Trades" on Apple Podcasts, Spotify, or your preferred platform. Share this episode with aspiring and established leaders, and stay tuned for more insights on driving business success and personal leadership growth.