security breach

Server & Hosting

A security vulnerability is a flaw in software that allows someone to gain unauthorized access. In WordPress sites, most vulnerabilities don't originate in the core, which is generally well-maintained, but rather in plugins and themes.

The typical process is unremarkable. A vulnerability is disclosed so that operators can update. Within hours, automated programs scan half the network for precisely that version. Anyone who doesn't update within a few days is caught. Not targeted, but targeted en masse.

For example, in the case of a known vulnerability in a widely used form plugin, less than 48 hours passed between its publication and the first automated attacks. The affected websites were those whose operators had done nothing wrong, except for not updating their sites for a week.

Therefore, what's effective isn't miracle tools, but routine: timely updates, daily backups off-server, two-factor authentication in the backend, a firewall in front of the application, and as few plugins as possible. Every additional plugin is another vulnerability.

Back to the glossary