WordPress Plugins: 5 Hours Is All Attackers Need
Patchstack’s State of WordPress Security in 2026 whitepaper recorded 11,334 new vulnerabilities across the WordPress ecosystem in 2025, a 42 percent increase year on year, with a median time from public disclosure to mass exploitation of just 5 hours. The average WordPress installation runs 20 to 30 plugins. Each one is a separate piece of software with its own update cycle, and the data is specific about where the real risk sits: it’s almost never WordPress core.
Key takeaways
- The median window from disclosure to mass exploitation is 5 hours Patchstack’s 2026 data means a patch delayed by even a day or two routinely means attackers already had a working exploit before you updated.
- Plugins, not WordPress core, drive the overwhelming majority of compromises Multiple 2026 sources converge on plugins as the entry point in roughly 95 percent of hacked sites, with core software flaws a small minority.
- Real, named, high-install-count plugins keep getting hit 2026 saw critical vulnerabilities in plugins with millions of active installs, including a backup plugin affecting over 3 million sites and a premium plugin supply-chain compromise.
The Scale, in Specific 2026 Numbers
Patchstack's whitepaper puts the 2025 vulnerability count at 11,334, a 42% jump from the prior year, and that pace has continued into 2026 at over 250 new plugin vulnerability disclosures weekly. Of those, 43% are exploitable without any authentication at all, meaning an attacker doesn't need a valid account or stolen credentials to use them, just a known-vulnerable plugin version running on a reachable site. Separately, Wordfence's network reports blocking roughly 55 million exploit attempts and over 6.4 billion brute force attacks every month, and industry figures citing WPMayor and Sophos put the total at approximately 13,000 WordPress sites hacked daily, close to 4.7 million a year.
2026 produced several concrete, named cases illustrating the scale at the individual-plugin level. A critical flaw in the Forminator Forms plugin, installed on over 600,000 sites, left roughly half of them, over 300,000 sites, potentially exposed. A separate SQL injection vulnerability in the All-in-One WP Migration and Backup plugin, with over 5 million active deployments, left an estimated 3.2 million sites running a vulnerable version weeks after the patch shipped, since only 35% of installations had updated by the time the figure was reported. June 2026 alone saw six separate CVSS 9.8 (critical severity) vulnerabilities actively exploited simultaneously across plugins collectively installed on over 1.14 million sites, including a supply-chain compromise of a premium, paid plugin, not just free ones.
If your update process depends on someone manually checking for patches on a weekly or monthly schedule, you are structurally behind the median 5-hour exploitation window. Enabling automatic updates for plugins, with a tested staging environment to catch rare compatibility breaks, closes that gap far more reliably than a manual review habit.
Why Patching Fast Still Isn't Enough on Its Own
Patch availability and actual patch adoption are two different numbers, and the gap between them is where most real-world compromise happens. The All-in-One WP Migration case is a clear example: two weeks after a related fix shipped, 65% of installations were still unpatched. A separate case, a WooCommerce-related vulnerability, was still actively yielding results for attackers seven months after its fix was released, a vulnerability that simply doesn't expire from an attacker's perspective as long as unpatched installations remain reachable.
This is also why the data specifically notes that 87.8% of exploits bypass standard hosting-level defenses, a figure worth sitting with: generic server hardening, the kind most hosting plans include by default, isn't built to catch plugin-specific logic flaws, since those vulnerabilities exist inside the application layer, not the server configuration. Site-level, plugin-aware protection (a security plugin with active threat intelligence, or a web application firewall tuned to WordPress-specific attack patterns) addresses a meaningfully different layer than generic hosting security, and the data suggests most sites are relying on the layer that doesn't actually catch most of what's hitting them.
What Actually Reduces This Risk
Practical defenses that address the documented attack pattern
The median 5-hour exploitation window makes manual, periodic review structurally too slow.
The average site runs 20 to 30 plugins, each one a separate, independently maintained attack surface.
87.8% of exploits are documented as bypassing standard hosting-level defenses alone.
An unmaintained plugin with a known vulnerability never gets patched at all.
73% of site owners reportedly have no recovery plan in place.
Who Should Weight This Most Heavily
- Automatic updates directly address the documented 5-hour exploitation window
- A minimal, actively maintained plugin set meaningfully shrinks the real attack surface
- WordPress core itself remains comparatively well-secured against this specific risk category
- Patch availability and actual adoption remain a large, documented gap
- Standard hosting-level defenses alone don’t catch most plugin-specific exploits
- Even high-install-count, well-known plugins have shipped critical vulnerabilities in 2026
Comparing WordPress hosting with built-in security
See our full hosting guide for shared, VPS, cloud and WordPress-specific hosting comparisons.
Our Sources
Where this comes from
The core statistics here are drawn directly from Patchstack’s State of WordPress Security in 2026 whitepaper, Wordfence’s published monthly network defense data, and multiple named, dated 2026 security incident reports (SecurityWeek, individual plugin CVE disclosures), cross-checked across independent sources for consistency.
-
Patchstack 2026 whitepaper cited directly
The 11,334 vulnerability count, 42% year-on-year increase, and 5-hour median exploitation window drawn from this specific, named, dated report.
-
Named 2026 incidents cited by plugin and install count
The Forminator Forms and All-in-One WP Migration cases drawn from specific, dated SecurityWeek reporting and CVE disclosures.
-
Wordfence network data cited directly
Monthly exploit-attempt and brute-force-attack figures drawn from Wordfence’s own published network defense statistics.
Frequently Asked Questions
Frequently asked questions
How quickly do attackers exploit newly disclosed WordPress vulnerabilities?
Patchstack’s 2026 data puts the median time from public disclosure to mass exploitation at just 5 hours, meaning a delayed update routinely means attackers already have a working exploit before a site is patched.
Is WordPress core software itself the main security risk?
No. Multiple 2026 sources attribute roughly 95% of compromises to the plugin ecosystem specifically, not WordPress core, which maintains a comparatively strong security track record.
Does good hosting protect against plugin vulnerabilities?
Not fully. 87.8% of exploits are documented as bypassing standard hosting-level defenses, since plugin vulnerabilities typically exist at the application layer rather than the server configuration layer hosting security addresses.
How many WordPress sites are hacked per day?
Industry figures citing WPMayor and Sophos put the total at approximately 13,000 WordPress sites hacked daily, totaling roughly 4.7 million annually.
Why do vulnerabilities in popular, high-install-count plugins remain dangerous for months?
Patch availability and actual adoption are different numbers. One documented 2026 case saw 65% of installations still unpatched two weeks after a fix shipped, and another vulnerability was still yielding results for attackers seven months after its patch was released.
Final take
- The median exploitation window is 5 hours, per Patchstack's 2026 whitepaper
- Roughly 95% of WordPress compromises start with plugins, not core software
- 87.8% of exploits bypass standard hosting-level defenses alone
WordPress’s real security problem is specific and well-documented: a 5-hour median window from vulnerability disclosure to mass exploitation, a plugin ecosystem averaging 20 to 30 installs per site, and standard hosting defenses that don’t catch most of what’s actually hitting sites. The 2026 data points to a clear, practical response rather than a vague call for vigilance: automatic updates that close the patching gap, a minimal and actively maintained plugin set, and WordPress-specific security monitoring layered on top of, not instead of, good hosting.