Common web software flaw could expose Poland’s government sites to hackers
Poland warned that WordPress flaws could let hackers seize government sites. The same weakness could spread across courts, hospitals and airports at once.

Poland warned on Aug. 5 that critical security vulnerabilities in WordPress could let cybercriminals compromise government websites and trigger a critical incident. The danger lies in a familiar piece of web software used to organize and display content, where one common flaw can become a common point of failure across many public sites at once.
CERT Polska, the national cyber response team, described in its 2024 annual report how it handles incidents and threats across the Polish internet, including warning lists and incident response. Its earlier 2018 report showed how busy that battlefield had already become: phishing accounted for about 44% of incidents that year, with malware distribution and spam also among the most common cases.
The warning lands in a country that has already seen digital attacks used to spread fear and steal data. In March 2021, hackers broke into two Polish government websites and briefly used them to circulate false claims about a non-existent radioactive threat. In February 2022, a ransomware attack on an independent public health-care facility encrypted personal data belonging to 30,000 patients and more than 1,000 employees.
Hospitals have remained a repeated target. Reports in 2025 said Polish hospitals were hit by cyberattacks that in some cases suspended operations and led to data theft, a direct threat to patient care as well as privacy. Those incidents show how quickly an intrusion on a website or network can move beyond IT and into emergency rooms, admissions desks and back-office systems that patients and staff rely on every day.
The threat is not limited to public-facing portals. In January 2026, the Polish government said it had stopped cyberattacks on energy infrastructure, underscoring how the same hostile activity can reach deeper into national systems. CERT Polska has also published a vulnerability notice for Quick.CMS software, another reminder that widely used content-management systems can expose many sites through the same technical weak point.
This article was produced by Prism’s automated news system from verified source data, official records, and press releases, then run through automated quality and moderation checks before publishing. The system is built and supervised by the people who set the standards it runs under. Read our full AI policy.
Did this article answer your question?

