Your WordPress Site Was Attacked Today. Here's What the Person Who Approved It Needs to See.
Your WordPress Site Was Attacked Today. Here’s What the Person Who Approved It Needs to See.
The WordPress site you approved is fielding attacks every 32 minutes. When the wrong one lands, the average SME pays $8,000 just to recover — and 60% of those businesses don’t survive the next six months.
WordPress just lost market share for the first time in over a decade. Between December 2025 and May 2026, its share dropped from 43.2% to 41.9% — six consecutive months of decline driven by the Automattic vs. WP Engine lawsuit that froze contributor confidence, shook hosting reliability, and is still active in court as of March 2026. Shopify, Wix, and Squarespace gained ground in the same period. For an SME owner, the implication is not philosophical. The plugins your site depends on are built and maintained by contributors whose participation has stalled. Hosting companies caught in the crossfire have faced access revocations and injunctions. The ecosystem you trusted when you approved the platform is operating under conditions that did not exist when that decision was made — and if you have no migration plan, you are carrying platform risk that was never priced into the original approval.
What makes that risk expensive is what is happening to the platform’s security layer at the same time. In 2025, 11,334 vulnerabilities were discovered in the WordPress ecosystem — 91% of them in plugins — with exploits typically launching within 5 hours of public disclosure. In April 2026, backdoors were planted in over 30 plugins from the Essential Plugins portfolio and sat dormant for months before activating across every installed site simultaneously. Smart Slider 3 Pro, installed on 800,000 websites, was compromised through the official WordPress update channel — the attacker used the legitimate update mechanism as the delivery vehicle. The Elementor Ally plugin exposed customer databases on 250,000+ sites through SQL injection, meaning an attacker could read, copy, or erase customer records without touching the site’s visible appearance — customers would not know, and you might not either until it surfaces in a call or a complaint. Sucuri documented 8,452 defacement incidents in their 2024 annual analysis of 70.8 million scans, where the site’s content is visibly replaced with the attacker’s message. Each of these incidents reached a business owner the same way: not from a dashboard, but from someone else noticing first.
None of this requires a developer to assess. Before your next leadership meeting, three questions are worth answering. First: who is responsible for auditing and updating your WordPress plugins, and when did they last do it? The average WordPress site runs plugins 6–12 months out of date, and 30–40% are already running at least one known, publicly disclosed vulnerability. Second: when was your last backup tested — not taken, but actually restored and verified on a clean test environment? An untested backup is an assumption, not a recovery plan. Third: what would it cost to migrate off WordPress if the platform continues to contract or a breach forces the issue? Migration involves content, design, SEO, integrations, and developer time. The organisations that price that number before they need it are the ones that make clear-headed decisions — not reactive ones.
Drop your hosting provider, rough plugin count, and date of your last security review in the comments. I’ll reply with a free WordPress platform risk scorecard — so you know exactly where your exposure sits before something forces the conversation.
Written by Mohd Hanafiah
Freelance developer and automation specialist from Malaysia. I build Astro sites, Flutter apps, AI automation workflows, and coach developers.
Work with me →