← The Log
Security

Millions of attacks hit outdated WordPress plugins

In October 2025, security firm Wordfence reported blocking 8.7 million attack attempts in just two days, all aimed at a handful of critical flaws in popular WordPress plugins that many sites had not yet updated. It fits a broader pattern: researchers say plugins and themes, not WordPress core, are a leading way sites get breached.

Attackers don't hand-pick victims here. They run automated scanners across the whole web, looking for any site still running a version with a known hole.

For a small or mid-size business on WordPress, the defense is unglamorous and effective: keep plugins and themes updated, delete the ones you don't use rather than leaving them dormant, and take nightly backups so you can recover fast. This is exactly what a maintenance plan is for. "It still works" isn't the same as "it's still safe," and the gap is measured in unpatched weeks.

Further reading: original source ↗

Want this handled for you?

This is exactly the kind of thing our website security work takes off your plate. Start with a free, no-pressure look at your site.

Come aboard
Get the Log by email

Plain-English notes on web, marketing, and getting found online. Occasional, no spam.