Websites
Your Website's Cybersecurity Matters More Than Ever
Website cybersecurity matters more today than ever before. Your company website is being scanned right now by bots that aren't looking for you, but for an outdated plugin. We look at how much attack automation has accelerated in 2026, how quickly WordPress vulnerabilities get exploited, and why artificial intelligence now plays for both the attackers and the defenders.

You have a company website. It works, customers send in forms, your offer is visible, everything looks fine. Except that in the background, whether you run a large company or a one-person business, someone, or rather something, has been trying to find a hole in it for weeks.
That's what the internet looks like today: automated bot traffic already accounts for 53% of all traffic online, and 40% of it comes from bots with malicious intent. Humans now generate less than half (47%) of internet traffic, according to the latest 2026 Bad Bot Report by Imperva (Thales), based on data from 2025. The same report shows how much artificial intelligence contributes to that growth: the number of bot attacks using AI rose 12.5 times year over year. A large share of this traffic is precisely the scanning of websites for known vulnerabilities, outdated plugins and weak passwords. Website cybersecurity has stopped being a topic reserved for large companies and IT departments. It concerns every site connected to the internet, regardless of size or industry.
A large share of vulnerabilities (and attacks) concerns websites built on WordPress. First, it powers the largest part of the web, so WordPress vulnerabilities land on the front line of automated attacks almost by default: one working exploit can be fired at hundreds of millions of installations. Second, WordPress is open source, so attackers (just like defenders) can analyse it for weaknesses without any restrictions. Third, and probably most important in practice, WordPress builds its extensibility on plugins, and each of them, once it stops being updated by users and authors alike, becomes a separate attack vector independent of the core itself.
Why would anyone attack my website?
This is the question we hear from business owners most often, and it usually comes with an assumption: "I'm not a bank, I don't hold any secret data, why would anyone want my website?" The problem is that attackers almost never pick a target by hand, by company name. Instead of asking "how do I attack company X", they ask "find me 10,000 sites with this specific, known vulnerability". That is exactly what the automated bots described above do, scanning the whole internet without distinguishing between a large corporation and a sole trader.
What makes a site worth attacking rarely has anything to do with what the company actually does. What matters is what can be extracted from a compromised site:
- Server resources, the domain and its reputation in Google. After a takeover, the site starts publishing content its owner never created: pages targeting gambling, pharmaceutical or financial queries, mass-generated articles, or thousands of hidden links pointing to external services. The goal is simple: use the domain's existing history and search authority to rank something completely different.
- Data. If the site stores customer accounts, order data or contact forms, it becomes a target in itself. Not every company website holds something worth stealing, but an online store or a portal with user accounts is a different story.
- Access to the administrator account. Sometimes the target isn't the site itself but the person who has access to it. A compromised admin account allows attackers to change the site's content, install more plugins, add new users and extend access to other systems that person works with.
- Infrastructure for further attacks. A compromised site is often used as part of someone else's infrastructure: to send spam, host phishing pages, redirect users or hide malicious files.
In other words: you don't have to be an "interesting target" to get attacked. It's enough to be technically visible and vulnerable. Here's an example from our own backyard: a freshly set up VPS server, never "published" anywhere, logged more than 6,000 automated attack attempts in a single month.
WordPress vulnerabilities: why is this system the main target?
WordPress powers more than 41-43% of all websites in the world, more than all other CMS platforms combined. For an attacker that isn't a technical detail but an economic argument: one working exploit can be fired at hundreds of millions of installations at once, so it pays to invest in tools specialised for WordPress.
The scale of the phenomenon is visible in hard numbers from 2025 and 2026. According to the Patchstack report, 2025 alone saw 11,334 new vulnerabilities in the WordPress ecosystem, a 42% increase year over year. As many as 91% of them concerned plugins and only 9% themes. The WordPress core itself remains relatively secure, which confirms the point we made in our podcast episode: the problem is rarely WordPress itself, far more often it's what gets bolted onto it.
The catch is that the report was published at the beginning of 2026, and since then the number of discovered vulnerabilities and attack attempts has grown significantly. One look at the Wordfence database is enough: several vulnerabilities are reported every day.
From patch release to mass attack: why 5 hours is now the standard
This may be the most important number in this whole topic: the median time between a vulnerability being disclosed and its mass exploitation beginning is now just 5 hours. For less critical but still highly rated vulnerabilities, about half are exploited within the first 24 hours of publication.
The mechanism almost always looks the same:
- A security patch is published, often together with a technical description of the problem.
- Within a few hours, ready-made proof-of-concept code appears online (for example on GitHub).
- Automated bots start scanning the entire internet for sites running the vulnerable version of the plugin, by its characteristic file path, version number or signature in the page code.
- Successful cases are written into off-the-shelf attack tools and exploited at scale, with no human involved.
A good illustration is the July 2026 case of the vulnerabilities known as wp2shell (CVE-2026-63030 and CVE-2026-60137), which in combination allowed unauthenticated remote code execution (RCE) and a full site takeover. Mass exploitation began within hours of the first technical details being published, first to steal password hashes, then to take over servers entirely. The emergence of wp2shell was so serious that the WordPress team pushed automatic background updates to the vulnerable versions, but on some servers (for example shared hosting) that process could fail or be blocked, leaving the door open for attackers.
The practical conclusion is brutal: if you update plugins once a week or once a month, you are in practice leaving your site open to attack for most of the time between the vulnerability's publication and your reaction.
AI on both sides of the barricade
In 2026 this stopped being a theoretical debate and became everyday reality. AI is used for break-in attempts and data theft on an unprecedented scale, but it is also being deployed to find flaws and vulnerabilities in software faster and earlier than the attackers do.
AI as the attacker's tool
AI models and automated code analysis tools have radically sped up the process of finding and exploiting vulnerabilities. Bots can now identify vulnerable plugin versions across millions of sites in hours rather than days. This also lowers the barrier to entry for less experienced attackers, who previously lacked the technical knowledge to find and exploit such a flaw on their own.
AI as a defensive tool: the Core Security Initiative
AI is likewise being used to stay one step ahead of attackers. WordPress's own response to this trend is the Core Security Initiative, announced at the end of August 2026, a coordinated programme of the WordPress security team. The initiative rests on three pillars:
- a faster and more reliable process for releasing security patches,
- clearing the backlog of known, not yet patched reports,
- using AI to proactively detect vulnerabilities in the WordPress core, before security researchers or attackers themselves do.
Over the past year the number of security reports has risen sharply, largely thanks to AI models that make analysing code for vulnerabilities easier for anyone with access to them, not just specialised teams.
The context in which this initiative was born is worth adding: it was directly preceded by the emergency release of WordPress 7.0.2 in July 2026, patching the wp2shell vulnerability, by many accounts the most serious in years. That vulnerability was found by a researcher using an AI tool from OpenAI.
What all this means for the owner of an ordinary company website
You don't need to understand the technical details of PHP Object Injection to draw practical conclusions:
- Updates can't wait for a "convenient moment". With a median of 5 hours from patch release to mass attack, a weekly or monthly update cycle means a vulnerability window measured in days.
- The number of plugins matters. Since 91% of all vulnerabilities in the WordPress ecosystem concern plugins, every additional, rarely used plugin you install is another potential backdoor.
- "My WordPress is up to date" is not the same as "my site is secure". The WordPress core itself accounts for a negligible share of real-world vulnerabilities.
- Open user registration is a real risk, and not only for e-learning platforms or stores with customer accounts. As the Tutor LMS case shows, an ordinary account can be enough to reach a far more serious vulnerability.
- Monitoring and fast reaction now count for more than trying to eliminate risk entirely. No system will ever be free of vulnerabilities, but the time between a patch being released and you applying it makes an enormous difference.
Is it time to leave WordPress?
No, and the data above is not an argument for a panicked rebuild of your company website within a week. For many companies a new website simply isn't the answer today: if your company launched the current version a year ago, a rebuild may be out of the question for cost reasons. What makes sense regardless of the site's age is a change in how WordPress itself is managed: treating updates not as a chore to be postponed to a convenient moment, but as something that happens without delay, ideally with monitoring and a backup in case something goes wrong.
The situation is different if you are only planning a new website or genuinely facing a redesign decision. Then it is worth considering Astro as an alternative to WordPress in many cases. It's the approach in which we build most new websites today, precisely with this problem in mind. Astro generates static sites: it doesn't rely on a database or code executed in real time, and above all it doesn't depend to the same degree on a sprawling ecosystem of plugins that constantly need updating. That doesn't mean a site built with Astro is "unhackable", but it significantly narrows the attack surface, because most of the classic vectors disappear: vulnerable plugins, theme flaws and unpatched login panels, which account for the vast majority of the statistics described above.
If, after reading this article, you're asking yourself when someone last really checked your website's security, you probably have your answer, or at least a reason to verify it. We write more about what genuinely deserves attention when choosing and configuring hosting on our blog.
Summary
2026 shows clearly that website security is no longer a topic solely for the IT departments of large companies. The scale of attack automation, the speed at which new vulnerabilities are exploited and the growing role of AI on both sides mean that even a small company website on WordPress is a potential target today, not because someone singled you out, but because the bots will find you anyway. Prevention and a proactive stance are therefore essential to the cybersecurity of your company website.
If you're not sure what state your website's security is in today, how many plugins you have installed, whether they're all up to date, how many administrators have access and whether the backup can actually be restored, let's audit your website together and see how secure it really is.



