Skip to main content
Whitelam.MediaBook a call
What good looks likeAll insights

Is your WordPress site a security risk? Where the attacks get in.

By Whitelam Media5 min read

WordPress itself is well looked after. The risk sits in plugins, old server software and updates that never get installed, and attackers now move within hours of a hole being made public. Here's where the holes come from and what to do if you stay on WordPress.

WordPress runs 40.2% of all websites, according to W3Techs. That makes it the biggest single target on the web. The core software is well maintained and patched quickly. The risk sits around it: in the plugins, in the server software underneath and in how fast updates get installed.

Most security holes are in plugins.

Patchstack, a security company that tracks WordPress vulnerabilities, counted 11,334 new ones in 2025 in its State of WordPress Security report. That was 42% more than in 2024. 91% were in plugins and 9% in themes. WordPress itself had six, all of them low priority.

Core does still need updates. WordPress 7.1.1, released in September 2026, fixed eleven security issues, and sites with automatic background updates got it without anyone lifting a finger. Plugins work differently. Each one is written by a separate developer, who fixes problems on their own schedule. Patchstack found that 46% of the vulnerabilities reported in 2025 had no fix from the developer by the time they were made public.

Attackers move within hours.

Once a hole is public, the clock is short. For the vulnerabilities attacked most heavily in 2025, Patchstack put the weighted median time to the first mass attack at five hours. Plenty of sites take weeks to update, as the first example below shows.

All-in-One WP Migration is a backup plugin that WordPress.org lists on more than 5 million sites. In August 2026 the US National Vulnerability Database logged a flaw in every version up to 7.109. It let an attacker with no login pull data from the site's database and, once an administrator restored a backup, run their own code on the server. At the end of September 2026, WordPress.org's version figures still showed more than half of those sites on 7.109 or older.

Really Simple Security is a security plugin that WordPress.org now lists on more than 3 million sites. In November 2024 a flaw rated 9.8 out of 10 let anyone log in as any user, administrators included. It hit sites that had switched on the plugin's own two-factor login, a setting meant to make logins safer.

Paying for a plugin doesn't make it safer.

It's tempting to assume a paid plugin gets more care. Patchstack's data points the other way. Premium and freemium components made up 29% of the valid vulnerability reports it handled in 2025, and 76% of the flaws found in premium components were exploitable. Premium components also had three times as many vulnerabilities known to be used in real attacks as free ones, according to the same report.

Your host's firewall catches only a fraction.

Many owners assume their hosting company blocks attacks for them. Patchstack tested that. In its study of the defenses hosting companies typically use, they blocked only 12% of attacks aimed at WordPress-specific vulnerabilities. A broader second test found 26% of attacks blocked. Both results are in Patchstack's 2026 report.

Old server software adds to the risk.

WordPress runs on PHP, and old PHP versions no longer get security fixes. WordPress.org's figures for September 2026 show 37.6% of WordPress sites on a PHP version with no security support. Another 24.5% run PHP 8.2, whose security support ends in December 2026. Unless those sites move, more than six in ten WordPress sites will be on unsupported PHP in January 2027.

What a hack does to a B2B firm.

A hack doesn't always show on the home page. An attacker may hide spam pages under your domain, send some visitors to scam sites or copy what people type into your forms. Google can label a site "This site may be hacked" in its results, and the label stays until the site is cleaned and Google has checked it again. If a buyer sees that label while drawing up a shortlist, you won't hear from them. Then there's the cleanup: specialist time, a clean reinstall and every password changed.

If you're staying on WordPress, do these five things.

  • Delete the plugins you don't use. A deactivated plugin's files still sit on the server.
  • Turn on automatic updates for plugins you trust. WordPress has let you do this plugin by plugin since version 5.5 in August 2020. Check your key pages after each round.
  • Move to a supported PHP version. Most hosts let you switch in the control panel. Test on a copy of the site first.
  • Get warned about new holes. A vulnerability alert service tells you when a plugin you run has a known problem, and some block the attack until the fix ships.
  • Keep backups away from the server. Then test that one actually restores.

Questions to ask whoever looks after your site.

  • How many plugins do we run, and when was each one last updated?
  • Which PHP version are we on, and when does its support end?
  • If a hole in one of our plugins is made public tonight, who finds out and how soon is it patched?
  • Where are the backups kept, and when did we last restore one?
  • Who has an administrator login, and does everyone with one use two-factor login?

A vague answer to any of these is worth following up.

The other route is a site with no plugins to patch.

The other route is a site with no plugins to patch. On the stack we build with, the features plugins provide, like forms, search settings and image handling, are part of the site's own code. Every change is checked on a private preview before it goes live, and any release can be rolled back in one click. The hosting platform blocks denial-of-service attacks on every plan, and the editing system can show each person only the parts they're allowed to change.

A modern stack still needs security updates. In December 2025 a flaw rated 10 out of 10 in React, the code Next.js is built on, let attackers run their own code on affected sites without logging in, and those sites needed an urgent update. The difference is one codebase to update and test, with no plugins from dozens of separate developers. We monitor and update every site we run.

Our free Website Health Check is coming soon. It will check the security basics every site should have, and on WordPress it will flag a site that gives away its version and login details. Join the list and we'll tell you when it opens.

If the answer points to a rebuild, see how we rebuild legacy websites or book a call. For the running cost of the plugin route, read what WordPress plugins cost your business.

Working on a project?

Tell us what you're planning.

We'll read your brief and reply within one business day. No mailing list. No follow-ups unless you ask for them.

Services needed

We reply within one business day. No mailing list. No follow-ups unless you ask for them.

Let's talk

What are you trying to make happen?

Most projects start with a short conversation. We listen to the brief, ask the right questions and tell you straight what we can handle and how. The first call is free.

Prefer to pick a time? Book a 30-minute call.

Or email us directly at info@whitelam.media.