Your Router Is a Liability and Your WordPress Site Is a Door: This Week's Threats Explained
Two stories from this week’s vulnerability feed deserve your attention. Not because they are dramatic, but because the data is unusually clear about the risk to small businesses running commodity kit and unmanaged websites.
These are not theoretical attack chains. Both have publicly available exploit code. Both are remotely exploitable. Neither requires a sophisticated threat actor to weaponise.
The Router Problem Nobody Is Talking About
Three critical vulnerabilities hit consumer and small business routers this week, and the severity scores are not the kind that allow for comfortable inaction.
CVE-2026-82542 affects the Tenda HG10. CVSS score: 10.0, the maximum possible rating. The flaw sits in the router’s web administration interface. An attacker can send a crafted request to the IPv6 routing function and trigger a buffer overflow remotely, without authentication. The exploit is public. It requires no special access, no insider knowledge, no particularly skilled attacker.
Two separate vulnerabilities affect the D-Link DIR-825M, both scoring 9.9. CVE-2026-82592 hits the disk formatting handler. CVE-2026-82593 hits the LTE module firmware upgrade component. Both are stack-based buffer overflows. Both are remotely exploitable. Both have public exploit code.
The D-Link DIR-825M is the kind of router that ends up in small offices, back rooms, and secondary network segments. It is not an enterprise device. It is affordable, widely available, and, as of this week, actively dangerous to run unpatched.
The Tenda HG10 occupies similar territory: low cost, widely deployed in small business settings, and now carrying a maximum severity vulnerability with a public exploit.
What this actually means: If your office router is one of these models and you have not updated the firmware, your network perimeter has a publicly documented hole in it. Any attacker with a basic toolkit and internet access can reach it. The attack surface is not your data centre. It is the grey box plugged into the wall behind the reception desk.
Check your router model. Log into the admin interface and look at the firmware version. If you cannot do that yourself, call whoever manages your IT today, not this week, today.
WordPress: When Your Website Becomes the Attack Vector
The second story this week is the cluster of critical WordPress plugin and theme vulnerabilities disclosed on 29 August.
The one that warrants the most attention for small businesses is CVE-2026-15980, affecting the MyHome Core plugin. CVSS score: 9.8. The flaw allows an unauthenticated attacker, someone with no account, no password, no prior access, to generate an activation token for an unconfirmed user account and obtain a valid administrator authentication cookie.
Read that again. No credentials required. Administrator access obtained.
The conditions required for exploitation are specific: the MyHome theme must be running in legacy or WPBakery mode with frontend registration and confirmation email enabled. Not every site will meet all those conditions. But the sites that do are fully exposed, and the flaw is in versions up to and including 4.4.5.
Beyond that single CVE, the broader picture this week includes critical flaws in WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP. These are not obscure plugins used by a handful of developers. GiveWP is one of the most widely used donation management plugins on the web. Avada is one of the best-selling WordPress themes in history. WPMU DEV Dashboard is the management interface used by agencies managing dozens of client sites simultaneously.
What this actually means for small businesses: If you have a WordPress website, and a significant proportion of UK small businesses do, you are running software that may currently contain publicly known, critically rated vulnerabilities. Your website is not just a marketing brochure. It is a server. It is connected to your domain. It may have access to your customer data, your contact forms, your payment integrations.
An attacker who compromises your WordPress installation does not just deface your homepage. They can use it as a staging post for further attacks, exfiltrate data, deploy malware, or use your domain reputation to send phishing emails that bypass spam filters.
The pattern here is consistent with what we see across small business breach data. Attackers do not announce themselves. They find an unpatched plugin on a site that nobody has reviewed in six months, and they work quietly from there.
The Common Thread: Unmanaged Infrastructure
These two stories look different on the surface. One is about routers. One is about websites. The underlying problem is the same.
Small businesses accumulate infrastructure. A router here, a website there, a plugin added three years ago for a feature nobody uses anymore. Nobody is responsible for tracking whether any of it is still current. Nobody receives the CVE alerts. Nobody is checking the firmware version on the device in the corner.
This is not a failure of intention. It is a failure of process. There is no system in place to catch these things. And in the absence of a system, nothing gets caught until something goes wrong.
The vulnerability intelligence that arrives every week is not noise. It is a map of where the doors are currently open. This week, the doors are in your router and your website. Next week they will be somewhere else. The question is whether you have a process to find out, or whether you are waiting to learn about it from a breach notification.
How to Turn This Into a Competitive Advantage
Most of your competitors have the same unmanaged infrastructure problem. They have the same ageing router firmware, the same unreviewed WordPress plugins, the same absence of a patching process.
Businesses that build a basic patching cadence, even a monthly review of critical devices and website software, can demonstrate something genuinely rare: that they are a safer partner to work with than the alternative.
For businesses that handle client data, professional services firms, accountants, legal practices, healthcare providers, the ability to say “we have a documented patching process and we review critical vulnerabilities as they are published” is a material differentiator. Clients are increasingly asking about this during procurement. Cyber Essentials certification, which covers patch management, provides the framework. But the discipline has to be real, not a box ticked once and forgotten.
How to Sell This to Your Board
Three arguments that will survive a budget conversation:
The exploit is already public. These are not speculative future risks. CVE-2026-82542 has a CVSS score of 10.0 and a publicly available exploit. The effort required to use it is minimal. The cost of not patching is not hypothetical.
Your website is infrastructure, not a brochure. If your WordPress site is compromised, the consequences extend beyond a defaced homepage. Customer data, domain reputation, and email deliverability are all at risk. The business continuity cost of a compromised website is measurable and significant.
The cost of prevention is low. Router firmware updates are free. WordPress plugin updates are free. A monthly review of critical infrastructure takes one person a few hours. The cost of a breach is not.
What to Do Before the End of This Week
1. Identify your router make and model. Look for a label on the device or log into the admin interface. If you have a D-Link DIR-825M or a Tenda HG10, check the manufacturer’s website for a firmware update immediately. If your model is end-of-life with no patch available, begin the process of replacing it.
2. Log into your WordPress admin panel. Go to Dashboard, then Updates. If you have pending plugin or theme updates, run them now. If you are running MyHome Core, check whether you are on a version above 4.4.5. If you are running Avada, GiveWP, TranslatePress, Pods, or WPMU DEV Dashboard, check for updates for those as well.
3. Audit which plugins are actually in use. Deactivate and delete any plugin that is not actively serving a function. Unused plugins that are not updated are vulnerabilities waiting to be found.
4. Ask your IT support or MSP a direct question. Have they reviewed the CVEs published this week? Do they have a process for monitoring critical vulnerability disclosures? If the answer is vague, that is the real finding from this week’s intelligence.
5. Set a monthly reminder. Patch management does not need to be sophisticated. It needs to be consistent. One hour per month reviewing your router firmware, WordPress plugins, and any other externally accessible software will catch the majority of critical risks before they become incidents.
If this episode was useful, follow the show wherever you listen. Leave a rating or review if you have a moment; it genuinely helps more business owners find the programme. Drop a comment with your questions or with what you found when you checked your router model. And if someone you know is running a WordPress site or a small office network with no one watching it, share this with them. It might be the most useful thing they hear this week.