NITDA Warns WordPress Users of Vulnerability Allowing Site Takeover
NITDA Warns WordPress Users of Site Takeover Vulnerability

The National Information Technology Development Agency (NITDA) has issued an urgent warning to WordPress users in Nigeria about a critical vulnerability that could allow attackers to gain full control of their websites. The advisory, released on August 12, 2026, highlights the severity of the flaw, which affects millions of sites globally, and urges immediate action to mitigate risks.

Critical Vulnerability Details

According to NITDA, the vulnerability exists in certain WordPress plugins and themes, enabling malicious actors to execute arbitrary code, steal sensitive data, or completely hijack a website. The agency did not specify the exact plugins affected but emphasized that the flaw is being actively exploited in the wild, with reports of compromised sites increasing over the past weeks.

NITDA's Cybersecurity Department, in a statement signed by its Head of Cyber Security, Dr. Aliyu Ibrahim, said: "This vulnerability poses a significant threat to the integrity of online platforms, especially for businesses and government agencies that rely on WordPress for their digital presence. We strongly advise all users to update their installations and plugins to the latest versions immediately."

Wide Pickt banner — collaborative shopping lists app for Telegram, phone mockup with grocery list

Impact on Nigerian Users

Nigeria has a large number of WordPress-based websites, including news portals, e-commerce stores, and corporate sites. NITDA estimates that over 40% of Nigerian websites use WordPress, making them potential targets. The agency warns that a successful attack could lead to defacement, data breaches, and loss of customer trust, with financial implications running into millions of naira.

The advisory comes amid a rise in cyberattacks on critical infrastructure in the country. In the first half of 2026, NITDA reported a 25% increase in cyber incidents compared to the previous year, with website compromises being the most common type.

Recommended Actions for Website Owners

NITDA has outlined a set of recommended actions for WordPress users to protect their sites. These include updating WordPress core, plugins, and themes to the latest versions; removing any unused or outdated plugins; and enabling two-factor authentication for admin accounts. The agency also advises regular backups and the use of security plugins to monitor for suspicious activity.

"Website owners should also review their user roles and permissions, ensuring that only trusted individuals have administrative access," Dr. Ibrahim added. "In case of a suspected compromise, they should immediately change all passwords, scan their systems for malware, and report the incident to NITDA's Computer Security Incident Response Team (CSIRT)."

Broader Cybersecurity Context

The warning is part of NITDA's ongoing efforts to strengthen Nigeria's cybersecurity posture. The agency has been conducting awareness campaigns and training programs for public and private sector organizations. This latest advisory underscores the importance of proactive security measures in an increasingly digital economy.

NITDA also reminded users that WordPress is an open-source platform, and its security depends on the vigilance of the community. The agency encourages developers to follow secure coding practices and promptly address any vulnerabilities discovered in their products.

In response to the vulnerability, WordPress.org has already released patches for the affected components, and users are strongly encouraged to apply them without delay. NITDA will continue to monitor the situation and provide updates as necessary.

Pickt after-article banner — collaborative shopping lists app with family illustration