In October 2025, security firm Wordfence reported blocking 8.7 million attack attempts in just two days, all aimed at a handful of critical flaws in popular WordPress plugins that many sites had not yet updated. It fits a broader pattern: researchers say plugins and themes, not WordPress core, are a leading way sites get breached.
Attackers don't hand-pick victims here. They run automated scanners across the whole web, looking for any site still running a version with a known hole.
For a small or mid-size business on WordPress, the defense is unglamorous and effective: keep plugins and themes updated, delete the ones you don't use rather than leaving them dormant, and take nightly backups so you can recover fast. This is exactly what a maintenance plan is for. "It still works" isn't the same as "it's still safe," and the gap is measured in unpatched weeks.
Further reading: original source ↗
Want this handled for you?
This is exactly the kind of thing our website security work takes off your plate. Start with a free, no-pressure look at your site.
Come aboard