Hardening an Estate Agency Site That Handled Sensitive Client Data on an Unpatched Build
An estate agency's WordPress site collected viewing requests, mortgage-in-principle documents and tenant referencing details — but hadn't had a core or plugin update applied in over a year.
The Challenge
The agency wasn't looking to replace their site — it worked for their branch listings and content — but a routine check flagged an outdated WordPress core version and several plugins with known, publicly disclosed vulnerabilities. Given the site collected referencing documents and personal details from prospective tenants, the risk wasn't theoretical.
Our Strategy
We recommended a security assessment before touching anything, so fixes were prioritised by actual risk rather than guesswork, followed by a maintenance plan so the site wouldn't drift back into the same state.
Implementation
- Ran a full vulnerability assessment across core, theme and plugins
- Patched WordPress core and updated or replaced plugins with known vulnerabilities
- Reviewed file upload handling on the referencing form and added stricter validation
- Added security headers and enforced HTTPS site-wide
- Set up a scheduled maintenance plan covering updates, backups and monitoring
Technology
Security
The assessment followed the same structure described on our security assessment page: identify what's exposed, prioritise by real-world risk, fix the highest-risk items first, then put monitoring in place so new issues are caught early rather than discovered during an incident.
Results
- Every plugin with a publicly disclosed vulnerability was updated or replaced
- The referencing document upload form now validates file types and sizes server-side instead of relying on the browser alone
- The site is now on a scheduled update and monitoring plan instead of running unattended for months at a time
Client name withheld at their request. Specific vulnerability details are not published here, in line with responsible disclosure practice and because the client's systems remain in production.
Related Reading
Not Sure How Exposed Your Existing Site Is?
Request a security assessment before it becomes an incident.
Free Website & Security Audit