Web

The Biggest Risk to WordPress Security in 2026

It takes hackers an average of five hours to begin exploiting a new vulnerability after it’s published. And Patchstack’s latest State of WordPress Security in 2026 report found 11,334 new vulnerabilities across the WordPress ecosystem last year (and the vast majority weren’t in WordPress itself). Wordfence separately reported blocking over 8.7 million attack attempts in just two days in October 2025, aimed at two plugins that had actually been patched more than a year earlier.

The speed of cyber threats targeting WordPress websites has accelerated dramatically – a 42% increase from 2024. WordPress powers a huge share of the web, and the threat landscape around it is becoming increasingly volatile.

 

Vulnerabilities in the WordPress Ecosystem

Of the 11,334 vulnerabilities, only six flaws were found in WordPress core. The bulk of the security flaws lies with third-party plugins that businesses rely on every day:

Vulnerability Target Share of Total Vulnerabilities Primary Risk Factors
WordPress Core

< 1% (6 total)

Core remains highly secure and monitored.
WordPress Themes

9%

Moderate risk, often tied to design frameworks.

WordPress Plugins

91%

Highest risk, driven by third-party integrations and unverified code.

This vulnerability gap is expanding due to two growing industry trends: the rise of AI-assisted threat automation and the popularity of “vibe coding” – where developers rapidly ship plugin features without following industry best practices when it comes to security. When that happens, the plugin introduces critical backdoors into an otherwise secure hosting setup, and attackers now have the tools to find those doors within hours. A gap of even a few hours between a vulnerability’s public disclosure and a deployed patch creates an opportunity window for automated botnets.

While new plugins are a security risk, old plugins can be just as dangerous – take the Wordfence attack for example. Security patches are not a guarantee against future attacks and unmaintained sites will always be prime targets. Leaving inactive, outdated, or unmonitored plugins on a server creates lingering access points that attackers continuously scan for.

 

Our Approach to Website Security

At Herdl, we believe that the best offence is a good defence. That five-hour window is just too fast to rely on a once-a-month maintenance routine (gaps of even a few days can be risky). When automated hacking tools can weaponise fresh vulnerabilities in a matter of hours, that changes what a responsible aftercare plan needs to look like:

  • Security has to be continuous, not periodic
  • Security can’t be treated as a reactive, “post-breach” fix
  • Effective security requires pre-emptive controls and active oversight
  • Recent and reliable backups are a necessity, not a nice-to-have

At Herdl, our holistic approach focuses on reducing the attack surface of websites all the way from the server level right through to the browser:

[ Server-Level Security ] ➔ [ Continuous Vulnerability Scans ] 
➔ [ Curated Plugin Suite ] ➔ [ Off-Site Daily Backups ]

We maintain a tightly curated list of Herdl-approved plugins that are installed for every site we onboard as part of our Aftercare service. These plugins are in active development and have a track record of being patched quickly if/when issues are found. We keep a live inventory of what’s installed across every site, with ongoing vulnerability checks rather than a monthly glance. We keep continuous watch over all the sites in our care and daily off-site backups are not optional. Because of the high rate of new vulnerabilities being detected in the ecosystem, moving fast is only safe if you can undo it. Daily off-site backups provide a safe space to return to if anything goes wrong.

 

The Takeaway?

These security vulnerabilities represent real operational risks. A compromised website can lead to site downtime, customers being redirected to phishing sites or fraudulent stores, revenue loss, search engine penalisation, customer complaints, and damaged brand reputation. If you’re responsible for a WordPress site, you need to ensure your digital assets are protected. Make sure whoever manages your website care is doing the following:

  1. Auditing your site to remove unused plugins. Standardise on active, thoroughly vetted plugins from reputable developers who rapidly release security patches.
  2. Moving away from static monthly updates toward continuous vulnerability monitoring that flags emerging plugin flaws in real time.
  3. Maintaining automated, off-site daily backups as a safety net. Reliable recovery points ensure that if an incident occurs, your site can be restored quickly without data loss.
  4. Ensure security measures extend across all layers – including server-level firewalls, strict user access controls, and active web application defenses.

 

The Last Word

The headline figure worth remembering is five hours. That’s roughly how long you have, on average, between a new vulnerability going public and attackers starting to exploit it. No maintenance schedule built around monthly check-ins can realistically compete with that. A basic maintenance plan lowers risk, but there need to be other safeguards in place. If you’d like to hear more about our Aftercare service and how we support our clients’ security defenses, reach out to our team.

Want more?

Ready to grow your business?

Whether you’re looking to improve your website, boost your visibility, or scale your digital marketing, we’re here to help. Get in touch using the form below or call us on 0116 3400 442

"*" indicates required fields

This field is for validation purposes and should be left unchanged.