The Dutch data protection authority, the Autoriteit Persoonsgegevens, published advice for those who want to use cheap wordpress plugins and think that checks the box for compliance. The DPA is telling organizations hit by recently disclosed WordPress flaws. WordPress runs a large share of sites in the Netherlands. The holes are being exploited now. Breach filings at the AP have jumped.
What an attacker gets
WordPress is the publishing stack. Abuse of these bugs can mean takeover of the install. After that, the attacker can reach whatever the site held: admin and user accounts, content that was supposed to stay behind a login, and anything customers or visitors put through the site. Forum posts. Orders. Quotes. Consult bookings. Form fills.
That mix is enough for spam, targeted phishing, and malware. The AP wants controllers to treat those downstream uses as likely, not theoretical, once access looks real.
A fix is out. Many operators have not installed it. The National Cyber Security Centre has WordPress update guidance the AP points to.
What to do this week
Check the version you are running. Move to the current release. Then find out whether this install was exposed and whether anyone used the bug. Hosts and IT vendors can help pull logs for indicators of compromise.
If you find signs of abuse, run the incident plan. Do not wait for a perfect forensic novel before you treat it as a personal-data breach. The AP’s line is blunt: traces of misuse plus possible access to personal data means you assume a breach, and you assume the attacker may misuse what they took. File with the AP. A preliminary notice through the breach form is allowed. You are not supposed to sit on the clock while a long investigation finishes the exact count.
When to tell the people
Notification to individuals turns on risk. The AP filled in the gray areas that organizations like to hide in.
If you cannot exclude access from the logs, use the worst case: the attacker reached the personal data.
If special-category data is in play, including health, treat the risk as high and tell everyone affected as soon as you can.
If large sets of email addresses and phone numbers were reachable, treat that as high risk too and notify. Those lists are phishing fuel.
Tell people directly, promptly, and in language they can use. The AP’s victim-notice page is the how-to.
Why this travels outside the Netherlands
WordPress is not a Dutch product problem. Any controller with forms, shops, or member areas on an unpatched install is in the same fact pattern. GDPR’s 72-hour clock and high-risk individual notice do not pause for “we are still reading logs.” The Dutch note is useful because it names the failure mode: organizations decide the incident is small because they have not finished looking.
If you run WordPress for a business, a clinic, a school, or a membership site, patch first. Then prove from logs that nobody walked in. If you cannot prove that, notify the authority and write to the people whose inboxes and phone numbers were on the box. Waiting for certainty is how you miss the window and still have to explain the same facts later, with less goodwill.