WordPress powers over 40% of the internet. That makes it a big target - and the numbers from the past year show just how active attackers have been. Most businesses running WordPress have no idea their site is involved.

How often do you update your WordPress website?
If the answer is “when I remember” or “not sure”, you’re not alone – but it’s worth knowing what that’s actually means for you.
In 2025, researchers recorded 11,334 new vulnerabilities across the WordPress ecosystem*. That’s the highest number ever, and a 42% jump on the year before. Almost none of them were in WordPress itself – 91% were in plugins. Nearly 2,000 were rated high severity, and more high-severity vulnerabilities were found in 2025 than in the previous two years combined.
WordPress released an update (version 7.1.1) earlier this month that fixes 11 security weaknesses hackers could have used to break into websites, along with 36 other bugs**. Some of those bugs affect the editor people use to build and edit pages.
Several of the security problems were found using AI. Anthropic, the company behind the AI assistant Claude, and pwn.ai, a firm that uses AI to test websites for weak spots, are both credited with reporting issues.
Plugins are the weak point
91% of WordPress vulnerabilities in 2025 were found in plugins, not in WordPress itself. So every plugin you add is another door someone could try. And the problem isn’t just that the flaws exist, it’s how quickly they get used.
After a vulnerability is made public, the median time to first exploitation is five hours. Not five days… just five hours*.
That window matters because 46% of vulnerabilities had no fix available when they were made public. The plugin developer either hadn’t fixed it yet or, in some cases, may never fix it. In 2024, more than half of the plugin developers notified about security holes in their code didn’t release a fix before the problem went public. This is why it’s worth checking that the plugins you use are actively maintained and regularly updated.
What happens to sites that are compromised?
When bots or attackers get into a WordPress site, it’s often not obvious. Most businesses don’t find out because their homepage breaks. Instead, they find out because Google flags the site, because customers report being redirected somewhere strange, or because emails stop landing after the site’s been used to send spam.
In April 2026, attackers who had bought a set of more than 30 popular WordPress plugins activated a backdoor they’d hidden in them eight months earlier***. The changelog for the update read: “Check compatibility with WordPress version 6.8.2.” What it didn’t mention was the 191 additional lines of PHP that had been quietly included, code capable of remote code execution once triggered. Thousands of sites suddenly began showing spam links and fake pages that only Google could see. Business owners logging into their site saw nothing unusual, and many sites were still showing the spam even after the plugins were fixed.
When the plugin itself is the problem
Even regularly maintained sites have been caught out. Attackers don’t always target your site directly. Sometimes they target the plugins you rely on, as shown with the above example.
Gravity Forms, a premium plugin used by around a million sites, was compromised in a similar attack****. Malicious code was injected into manual installers downloaded from the official website.
GutenKit and Hunk Companion, two popular plugins, were exploited in October 2025, with nearly nine million attack attempts blocked in a two-week period*****.
These aren’t obscure, poorly maintained plugins, they’re tools that many organisations are using right now, and still using following these incidents.
Hitting “update all” isn’t the answer either
The instinct to just run all available updates is understandable, but it carries its own risks. Plugin conflicts are common, and a failed update can take down a page, a form, or in worse cases, the whole site. If you don’t have a staging environment to test against, and you’re not monitoring what changed after each update, you won’t always know when something has broken – or been broken on purpose.
One client came to us because their agency had simply updated the plugins, but a mismatch in versions between two meant that any changes to the website couldn’t be made. The website was essentially not working just because of two plugins being updated.
Good WordPress maintenance means testing updates before they go live, monitoring the site for unexpected changes, keeping an eye on newly published vulnerabilities for plugins you’re running, and having a rollback plan when something goes wrong.
It also means staying on top of plugins you’re no longer using. Deactivated plugins with known vulnerabilities are still exploitable. If it’s not needed, it should be removed.
What to do if your site hasn’t been looked at in a while
Start with an audit. That means checking which plugins and themes are installed and whether any have known vulnerabilities, looking for any signs of existing compromise, and reviewing who has admin access and whether those credentials are still secure. Question what plugins you have and whether they are still relevant – websites we inherit often have 50% of plugins they didn’t need. Then decide whether the remaining plugins can be replaced with a small amount of code or perhaps seeking plugins that do the job of multiple.
If that feels like a lot – it might be, but don’t skip this stage. Most businesses don’t have the time or the in-house knowledge to do this properly, which is exactly how sites end up left alone for months at a time and then the problem escalates, becoming much more expensive than the initial audit.
Next is having a proper maintenance schedule in place. Just like you get your boiler serviced every year, WordPress websites need regular attention to. We recommend a minimum of quarterly updates and we bring these forward if a vulnerability is announced.
WordPress maintenance isn’t a once-a-year task. The threat landscape moves quickly enough that a site left unmonitored for a few months can already be behind. That’s what our website maintenance and support service is built for – keeping things updated, tested, and secure, so you’re not finding out something’s wrong after the damage is done.
https://patchstack.com/whitepaper/state-of-wordpress-security-in-2026/
Patchstack's State of WordPress Security in 2026
https://www.therepository.email/wordpress-7-1-1-ships-11-security-fixes-credits-anthropic-and-pwn-ai-again
The Repository
https://cybersecuritynews.com/hackers-hide-backdoor-in-trusted-wordpress-plugins/
Cyber Security News
https://www.securityweek.com/hackers-inject-malware-into-gravity-forms-wordpress-plugin/
Security Week
https://www.bleepingcomputer.com/news/security/hackers-launch-mass-attacks-exploiting-outdated-wordpress-plugins/
Bleeping Computer





