Every compromised site I have cleaned in the last five years came in through one of three doors, and none of them required skill to open.
An abandoned plugin
Someone installed a plugin in 2019 for a feature the site no longer uses. The author stopped updating it in 2021. A vulnerability was published in 2023. Nobody noticed because the plugin still appeared to work. Deactivating is not enough — the files are still on disk and still reachable.
A reused password
An administrator account using a password that also appears in a breach dump from an unrelated service. There is no clever exploit here; an automated script simply logs in. Two-factor authentication ends this category entirely, and it takes five minutes to set up.
A backup nobody tested
This one does not cause the breach, it turns a bad day into a catastrophe. A backup that has been silently failing for eight months is worse than no backup, because you planned around having one. Restore a copy to a staging site once a quarter. If that feels like too much effort, it is exactly the effort you will wish you had spent.
What to actually do this week
Delete every plugin and theme you are not using rather than deactivating them. Turn on two-factor for every administrator. Test one restore. That is a couple of hours of work and it removes most of the realistic risk to a small business site.