How WordPress sites actually get hacked

Up Speed

Up Speed

Security
How WordPress sites actually get hacked

When people picture a website getting hacked, they picture a person. Someone deliberately targeting their business, typing furiously. That is almost never what happens.

The overwhelming majority of WordPress compromises are automated. A script crawls the web, finds a site running something outdated, and walks in. Nobody chose you. You just matched a pattern.

Understanding the actual entry points matters, because each one has a boring, specific fix.

1. A plugin or theme with a known vulnerability

This is the big one. WordPress core itself is maintained by a large security team and patched quickly. The risk lives in the tens of thousands of third-party plugins and themes bolted on top of it.

Here is the part most owners miss. When a plugin vulnerability is discovered, it gets published. Publicly. In a security database, with details. The patch ships the same day, but so does the roadmap for attacking every site that has not applied it yet. Automated scanners start sweeping for unpatched installs within hours.

So the window is not "some day, maybe". The window opens the moment the fix is announced, and it stays open on your site until you update.

The fix: update plugins and themes promptly, and remove anything you no longer use. A deactivated plugin still sits on the server and can still be exploited. Delete it, do not just switch it off.

2. Weak or reused admin credentials

Brute-force attacks are exactly what they sound like. A bot hits your login page over and over with common username and password combinations. "admin" plus something guessable is still a distressingly effective combination.

Reused passwords are worse. If you used the same password on your site as on a service that later suffered a breach, that pair is now in a public list. Bots test those lists against WordPress logins automatically. No guessing required.

The fix: a unique long password per site, no shared admin accounts, and two-factor authentication on every account that can reach the dashboard. Two-factor is the single highest-value thing you can turn on, because a stolen password stops being enough. On Up Speed, two-factor login is set up as part of the Professional plan, along with brute-force protection through iThemes hardening.

3. Compromised hosting or a neighbouring site

On cheap shared hosting, your site sits on a server with hundreds of others. If the isolation between accounts is poor and one of those neighbours gets infected, the malware can sometimes move sideways into your files.

This one is genuinely not your fault, which is precisely why it is so frustrating. You did everything right and inherited someone else's problem.

The fix: pick a host that isolates accounts properly, and keep your own clean off-site backup so you are never dependent on the host's copy of a server that just got compromised.

4. Stale user accounts nobody closed

The freelancer who redesigned your site in 2021 probably still has an administrator account. So might the marketing agency you stopped working with, and the developer who fixed one thing that one time.

Every one of those accounts is a working key to your site, sitting on a laptop you do not control, protected by a password you have never seen.

The fix: audit your user list. Delete accounts that are not in active use. For people who need access, give them the lowest role that lets them do their job. Almost nobody needs Administrator.

5. Nulled or pirated premium plugins

"Free download" versions of paid plugins are one of the most reliable ways to infect a site, because the malware is not a side effect. It is the entire business model. Someone paid to distribute that file, and they are getting their money back through your server.

The fix: buy the licence or use a free alternative. There is no third option that ends well.

What happens after they get in

Attackers rarely deface your homepage. That would tell you immediately, and they want time. Instead they inject spam links into your pages, redirect mobile visitors to a scam, quietly send bulk email from your server, or leave a backdoor file so they can return after you clean up.

Which is why sites are commonly infected for weeks before anyone notices, and why the first sign is often Google flagging you rather than anything you spot yourself.

Where ongoing care comes in

Every entry point above closes with routine maintenance. Updates applied on time. Old plugins removed. Strong credentials with two-factor. Unused accounts deleted. Someone actually looking at scan results.

None of it is difficult. It is just relentless, and it never finishes, which is exactly why it gets skipped on a busy month.

That is the work Up Speed takes over. Malware scanning, 24/7 uptime monitoring and tested updates run on every plan. The hardening layer, Wordfence firewall, iThemes configuration and two-factor login, comes with the Professional plan. And when something does get through, we fix it rather than emailing you an alert and wishing you luck. No plan makes a site impossible to attack, and anyone who tells you otherwise is selling something. What we can do is close the doors that are usually left open, and be the ones handling it when they are not.

Share this post

Start with a free WordPress site audit.

Send us your site and we will check its speed, security, backups, and update status, then write up what we found. A real person does the review.

  • No credit card required

  • No contracts, cancel anytime