Personally, what I'd do in such a situation is to contact a well-renowned hacker organization with experience in these matters (as for instance the CCC here in Germany) and ask for their assistance.
Alternatively, a tech publishing company could also be the right choice, preferably one with a legal department and experience in these things. He mentions that you should buy the issue of "Computer Active" that contains this article, so he probably took this route.
I also gave the DoH ample opportunity to fix the sites or shut them down.
I agree that there is a (minor) risk - but offset against hundreds of high profile sites being exploited, I think it's worthwhile.
We spoke to the overall owner of the sites and they did not object to myself or the magazine publishing this information.
That's...astonishing.
Sadly, it didn't transform into action.
I congratulate you for talking to the owners before publication, however.
What do you mean by this?
In the article you state:
> in many cases there is simply no way to contact the website owners
Do you simply refer to the owner of the parent domain name?
With some, we were able to contact the developers behind the sites. Others just didn't respond.
Basically - no one in the NHS or DoH knows who manages the thousands of .nhs.uk websites. We did our best to contact individual site owners and, where that was impossible, alerted the government directly.
Hope that clears it up.
From what I know vulnerability scanning (which is essentially what wpscan does) is a bit of a grey area under UK law.
It's been likened to someone "rattling the windows" of a house. They may be doing it with the intention of notifying the owner that he's left his house unlocked, or they may be doing it to attempt to gain unauthorised access..
The analogy isn't perfect but it's one I'd step carefully on.