Why your WordPress site keeps getting hacked

Every compromised site I have cleaned in the last five years came in through one of three doors, and none of them required skill to open.

An abandoned plugin

Someone installed a plugin in 2019 for a feature the site no longer uses. The author stopped updating it in 2021. A vulnerability was published in 2023. Nobody noticed because the plugin still appeared to work. Deactivating is not enough — the files are still on disk and still reachable.

A reused password

An administrator account using a password that also appears in a breach dump from an unrelated service. There is no clever exploit here; an automated script simply logs in. Two-factor authentication ends this category entirely, and it takes five minutes to set up.

A backup nobody tested

This one does not cause the breach, it turns a bad day into a catastrophe. A backup that has been silently failing for eight months is worse than no backup, because you planned around having one. Restore a copy to a staging site once a quarter. If that feels like too much effort, it is exactly the effort you will wish you had spent.

What to actually do this week

Delete every plugin and theme you are not using rather than deactivating them. Turn on two-factor for every administrator. Test one restore. That is a couple of hours of work and it removes most of the realistic risk to a small business site.

PreviousYour Web Developer Companion

Let's talk about your project

New build, rescue job, or a system nobody else wants to touch. Tell me the details and I will reply with an honest answer about whether I am the right person.

Message on WhatsApp