The Dutch authority advises WordPress users affected by a data breach

The Dutch Data Protection Authority (AP) has issued recommendations to WordPress users following the discovery of actively exploited vulnerabilities.

The authority found that flaws in the WordPress software are currently being exploited, resulting in data breaches. It considers that the organizations concerned do not always properly assess the risks and do not sufficiently inform the data subjects whose data have been compromised. Exploiting these vulnerabilities can allow attackers to take full control of WordPress systems, thereby accessing user information, site content, and customer data processed through forms or transactions. This data can then be used for phishing campaigns, spam sending, or malware distribution. The AP recommends that organizations check and update their WordPress version without delay and review connection logs for indicators of compromise.

In case of evidence of exploitation involving potential access to personal data, a breach must be presumed and notified to the AP, including via a preliminary notification. For informing the data subjects, the authority specifies that the risk must be considered high if access to the data cannot be excluded, if sensitive data are affected, or if large quantities of email addresses and phone numbers have been compromised. In such cases, the victims must be informed directly and without delay.

Informations complémentaires

L’analyse complète est réservée aux membres

Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.

Essayer gratuitement 14 jours · accès complet · sans carte bancaire