Welcome to the first issue of Website News to Know, our monthly roundup for business owners and government teams in Oklahoma. Each month we cover the website news that actually affects you, in plain language, with the action to take.
September was a busy month. A WordPress security flaw went from patch to active attack in hours, Google started another spam update, and accessibility lawsuits kept climbing. Here is the website news that mattered.

1. WordPress patched a critical flaw, and attackers moved the same day
On September 22, WordPress released version 7.1.2, a security release that fixes a flaw in how page templates are resolved. In the wrong conditions it can let an attacker run code on your server without logging in.
The timeline is the part that matters. The first attack attempt was recorded the same day the patch came out, attacks jumped more than tenfold the next day, and on September 25 CISA added the flaw to its Known Exploited Vulnerabilities catalog, which is the federal list of bugs under real-world attack. Versions 4.7.0 through 7.1.1 are affected, and fixes were issued back through older branches.
What to do: check your WordPress version today. If you are not on 7.1.2 (or the patched version of your branch, such as 7.0.6 or 6.9.9), update now. If your site runs WordPress 4.6 or older, it cannot be patched at all and needs to be rebuilt.
2. Millions of sites are still running a vulnerable backup plugin
A second-order SQL injection flaw in the All-in-One WP Migration and Backup plugin was disclosed on September 3. It is rated high severity, and it can let an attacker take over a site. The fix has been out since version 7.110.
The problem is adoption. The plugin is on more than 5 million sites, and SecurityWeek reported that only about a third had updated, leaving roughly 3.2 million sites exposed.
What to do: if you use this plugin, update it. More broadly, this is the case for having someone check your plugins monthly rather than once a year. Backup and migration plugins are a favorite target because they touch everything.
3. Google started a spam update on September 24
Google began rolling out its September 2026 spam update on September 24, and it is expected to take up to two weeks. That is unusually long. August's spam update finished in two days.
Spam updates target content and tactics that break Google's spam policies, so most honest local business sites are not the target. Still, rankings tend to bounce around while an update rolls out.
What to do: do not make big changes to your site in the middle of a rollout. Note the date in your analytics, wait for the update to finish, then compare a full two weeks before and after. If you did lose ground, read Google's spam policies before you start rewriting pages.
4. AI Mode keeps expanding, and Search Console is starting to show it
The biggest website news in search was AI Mode. Google spent September pushing it deeper into search results, including folding it into AI Overviews and powering it with a newer model. On the reporting side, Search Console has begun separating AI Mode queries and has widened access to its generative AI performance report.
That reporting is the useful part. For the first time you can start to see how much of your search visibility comes from AI answers rather than traditional blue links.
What to do: open Search Console and look for the generative AI section. Even a rough read tells you whether AI results are sending you traffic or absorbing it. Then judge your site by calls, forms, and quote requests, not by traffic alone.
5. Accessibility lawsuits kept coming, and widgets did not stop them
UsableNet's tracker counted 432 new digital accessibility lawsuits in August. Two numbers stand out. About a quarter of the defendants had been sued over accessibility before, and 134 of them were using a third-party accessibility widget when they were sued.
That is worth repeating, because these widgets are sold as protection. They are not. A widget layered on top of an inaccessible site leaves the underlying problems in place.
What to do: if someone sold you an accessibility overlay, treat it as a bandage, not a fix. For Oklahoma cities, counties, and school districts, the ADA Title II deadlines are April 26, 2027 for governments serving 50,000 or more people and April 26, 2028 for everyone else. The 2027 date is now about seven months out.
6. October is Cybersecurity Awareness Month
Cybersecurity Awareness Month starts October 1. It is a good excuse to do the boring work that prevents an expensive week later.
What to do: four quick checks. Confirm your backups actually restore, not just that they run. Remove admin accounts for people who left. Make sure your SSL certificate and domain are not about to expire. And ask whoever runs your website how quickly they apply security updates, because September showed that the window between a patch and an attack can be hours.
Our monthly website maintenance guide walks through the full routine.
What this website news means for your site
Sites on our maintenance plans were reviewed for both WordPress issues above, and core security updates are applied as part of the plan. If you are not sure whether your site is current, ask us and we will check it.
If nobody is watching your site right now, that is the real takeaway from September. The gap between a patch being published and attackers using it has shrunk to hours, so "we update it when we think about it" is no longer a plan.
Contact our team if you want a second set of eyes on your site.
Website news FAQ
How do I check what version of WordPress I have?
Log in to your dashboard. The version appears at the bottom right of the main screen, and under Updates in the left menu. If you cannot log in, ask whoever maintains the site.
My rankings dropped this week. Was it the Google spam update?
Maybe, but do not assume it. Updates cause volatility while they roll out, and rankings often settle. Check whether the drop lines up with the September 24 start date, and wait for the rollout to finish before making changes.
Do accessibility widgets make my site ADA compliant?
No. They can help with a few specific issues, but they do not fix the underlying code, and companies using them are still being sued. Real compliance means testing and fixing the site itself.
How often should website security updates be applied?
For most small business sites, monthly is the baseline, with critical security patches applied as soon as they are released. September's WordPress flaw was attacked within hours of the fix going out.
Sources
- WordPress: WordPress 7.1.2 security release
- CISA: Known Exploited Vulnerabilities catalog
- SecurityWeek: Over 3 million WordPress sites affected by migration plugin vulnerability
- Search Engine Roundtable: Google September 2026 spam update
- Search Engine Roundtable: September 2026 Google webmaster report
- UsableNet: Web accessibility lawsuit tracker
- CISA: Cybersecurity Awareness Month