Why WordPress Sites Get Hacked (and How to Keep Yours Safe)

Most WordPress hacks aren't personal. Here's what we've learned from cleaning up close to a hundred hacked sites: the real causes, and how to close each gap.

Most WordPress hacks aren’t personal. They’re automated. Bots scan the web around the clock looking for known weak spots, and the most common one is a poor-quality or outdated plugin. Weak or reused passwords, abandoned software, and old user accounts nobody removed make up most of the rest.

We’ve been maintaining WordPress sites since 2009, and along the way we’ve cleaned up close to a hundred hacked ones. Almost every time, the cause was something that could have been prevented. Here’s what we’ve learned.

It’s not personal

When a small business gets hacked, the first question is usually “Why us?” The honest answer is that nobody chose you. Automated tools scan millions of websites looking for the same handful of weaknesses, and they don’t care whether a site belongs to a bakery or a bank. If your site has a known weak spot, it will eventually be found.

That’s actually good news. It means most hacks can be prevented with the same steady habits.

The most common cause: poor-quality or outdated plugins

In our experience, this is the number one way attackers get in.

Plugins add features to WordPress, and most are written by small teams or individual developers. When someone discovers a security hole in a plugin, it’s usually fixed in an update and then announced publicly. From that moment, any site still running the old version is a target. Bots start looking for it quickly. According to Patchstack’s State of WordPress Security in 2026 report, about half of high-impact WordPress vulnerabilities were attacked within 24 hours of being made public.

Two things make this worse:

  • Poor-quality plugins. Some plugins are simply written with less care, and they tend to have more security holes.
  • Skipped updates. A fix only protects your site once it’s installed.

The wider data backs this up. According to the same report, 91% of the WordPress vulnerabilities discovered in 2025 were in plugins and 9% were in themes. Only six were found in WordPress itself, and all of them were low priority.

And the problem is growing. Patchstack counted 11,334 new WordPress vulnerabilities in 2025, 42% more than the year before, and the number of highly exploitable ones more than doubled. Older security holes don’t go away, either: only four of the ten vulnerabilities attackers targeted most in 2025 were discovered that year. The rest were older ones, aimed at sites still running outdated plugins.

How it’s prevented: keep plugins updated on a regular schedule, check the site after updating, and choose plugins with a good track record. Working on a large number of sites teaches you which plugins can be trusted and which to avoid.

Other common causes

Abandoned plugins. Some plugins stop getting updates when their developer moves on. If a security hole turns up later, it never gets fixed. Prevented by: reviewing plugins regularly and replacing abandoned ones.

Weak, reused, or leaked passwords. Attackers try common passwords, and passwords leaked from other companies’ data breaches, on WordPress logins everywhere. (Please, stop using “Password123.”) Prevented by: giving every account its own strong password, and using a password manager. You can also check whether your email address has turned up in a known data breach at Have I Been Pwned.

Old admin accounts nobody removed. A former employee’s or old designer’s login is an open door, especially if its password was weak or reused. Prevented by: reviewing who has access and removing anyone who no longer needs it.

Pirated premium plugins. “Free” copies of paid plugins, sometimes called nulled plugins, often come with malware built in. Prevented by: only installing plugins from the official WordPress directory or the developer’s own website.

Cheap shared hosting. On some low-cost hosting, sites share a server with weak separation between them, so one infected site can affect its neighbors. Prevented by: quality hosting where someone is managing and watching the server.

What we find after a hack

When we clean up a hacked site, the obvious problem, like a spam page or a redirect, is rarely the whole story. Attackers usually leave more behind:

  • Backdoors: hidden files that let them walk back in later
  • Unknown admin users: accounts they created for themselves
  • Spam pages and redirects: often only visible to Google or to visitors on phones

That’s why a quick fix so often fails. If the backdoor stays, or the original hole stays open, the site gets reinfected.

Is WordPress itself insecure?

No. WordPress itself is well maintained, security fixes are released quickly, and small security updates install automatically by default. Most risk comes from what gets added to it, like plugins and themes, and from how the site is looked after over time.

And very often, the weakest link isn’t the software at all. It’s someone’s password.

How ongoing care closes each gap

CauseWhat prevents it
Poor-quality or outdated pluginsRegular updates with checks afterward, and experience choosing reliable plugins
Abandoned pluginsRegular plugin reviews and replacements
Weak, reused, or leaked passwordsIndividual accounts, strong passwords, and a password manager
Old admin accountsRegular access reviews
Pirated pluginsLicensed plugins from trusted sources only
Cheap shared hostingManaged hosting with someone watching the server

Every plan we offer covers the technical side: updates, daily backups, security monitoring, and malware cleanup if something gets through. With Website Care, you also get a team that’s in your site regularly, making your changes, so problems get noticed sooner.

Compare plans and pricing →

Hacked right now? Get Emergency Help →

FAQ

Can a small business website really be a target?

Yes. Most attacks are automated, and they target weaknesses, not businesses. A small site with an outdated plugin is just as likely to be found as a large one.

Do security plugins prevent hacks?

They help. A good security plugin can block common attacks and alert you to problems. But it can’t fix an outdated plugin or a weak password. Security plugins work best alongside regular updates and good password habits.

How often should passwords be changed?

More important than how often is how strong and unique they are. Give every account its own strong password, and change it right away if it may have been exposed, like after a data breach or when someone leaves your team.

Jeffery Patch

Founder, Lead Geek · MaintainPress

Jeff has been building and looking after WordPress sites since 2009.

Rather hand it off?

Tell us what your site needs, and we'll recommend the right plan. Month-to-month, no contracts.