· updated 2026-10-07
In the incidents we have investigated, the most common entry vector was not a sophisticated attack. It was a known, publicly documented plugin vulnerability left unpatched for months.
Why it happens so fast
When a vulnerability is disclosed, its description is published with it. Within hours automated scripts appear that scan the internet for the vulnerable version. Your site is found not because anyone is interested in it, but because it matches a pattern.
Three risk sources that get missed
- Inactive plugins. A deactivated plugin is still files on the server. Some vulnerabilities work by calling the file directly, regardless of activation.
- Abandoned plugins. If the author no longer updates it, a patch will never come. Check the last update date.
- Plugins inside themes. Commercial themes often bundle libraries that update only with the theme.
A practical minimum
- Delete what you do not use — delete, not deactivate.
- Update on a schedule, with a backup first and a quick check after.
- Before installing anything new, check when it was last updated.
- Enable vulnerability alerts for the versions you run.
To find out whether you are currently running versions with known vulnerabilities, start with the free security check.