Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

There is no reliable global count or rate in these sources for how many WordPress websites get hacked. The available figures measure different things: disclosed vulnerabilities, firewall-blocked attacks, malware detections in a vendor’s monitored sites, and exploitation observed in selected vulnerabilities. They are useful security data, but they are not interchangeable counts of successful compromises.

How to read WordPress hacking statistics

A vulnerability is a weakness that may be disclosed, patched, left unpatched, or exploited under particular conditions. A firewall-blocked request is an attempted attack, not proof that a site was compromised. A malware detection says a provider found malware in sites it monitors; it does not count every infected WordPress site. These distinctions matter because the figures below come from different providers, collection systems, time periods, and definitions.

  • Vulnerability databases count disclosed or identified flaws, not hacked websites.
  • Firewall telemetry counts requests or attacks blocked by that provider, not necessarily unique attackers or successful account takeovers.
  • Malware detections describe findings in a provider’s monitored population, not a census of WordPress installations.
  • Exploitation observations show that a flaw was exploited in observed traffic or reported as exploited in the wild; they do not reveal how many sites were compromised.

WordPress security data: platform footprint

WordPress.org says WordPress powers more than 43% of the web, according to its security page accessed October 7, 2026. That describes platform prevalence. It is not a breach rate and does not mean that the same share of hacked websites runs WordPress. WordPress.org’s security overview also describes work across core, plugins, and themes, including code review and fixes released through bugfix releases.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Wordfence Q4 2025 threat data

Wordfence’s February 3, 2026 report covers its own vulnerability database and firewall and site-monitoring telemetry for Q4 2025. The figures below describe those respective datasets, not the entire WordPress ecosystem.

Metric Wordfence figure What it counts and what it does not
Vulnerabilities added 2,213 in Q4 2025; 131 were classified as high threat and 100 as common and dangerous Additions to Wordfence Intelligence’s database during the quarter, not sites hacked.
Unpatched vulnerabilities 905 at the end of Q4 2025 Reported vulnerabilities in Wordfence’s database still unpatched at that point; not a count of exposed websites.
Firewall activity 9.1 billion WAF attacks blocked in Q4 2025 Wordfence firewall telemetry, not unique attacks across all WordPress sites or confirmed compromises.
Brute-force activity 13.8 billion attacks blocked in Q4 2025, 28.0% lower quarter over quarter Blocked requests in the provider’s telemetry; the figure does not establish unique attackers or confirmed account takeovers.
Malware detections 467,000 sites in Q4 2025 Sites with malware detected in the population Wordfence protects, not all infected WordPress sites.

Source: Wordfence, “Quarterly WordPress Threat Intelligence Report – Q4 2025,” published February 3, 2026.

Patchstack’s 2025 WordPress ecosystem figures

Patchstack’s 2026 report uses its own ecosystem dataset and classifications. Its annual figures should not be added to Wordfence’s quarterly database or telemetry: the publishers’ collection systems and criteria differ.

Metric Patchstack figure Definition and scope
New ecosystem vulnerabilities 11,334 in 2025, 42% more than in 2024 Vulnerabilities found in Patchstack’s WordPress ecosystem dataset for 2025.
Actual threats 4,124, or 36% of the 2025 total Patchstack classified these as serious enough to require its RapidMitigate rules; this is the provider’s classification, not a number of successful hacks.
High-severity vulnerabilities 1,966, or 17% of the 2025 total Patchstack’s severity classification for its 2025 vulnerability dataset.
Fixes absent at disclosure 46% in Patchstack’s 2025 disclosure-timeline analysis Share of vulnerabilities in that analysis without a developer fix by public disclosure.

Source: Patchstack, “State of WordPress Security in 2026”.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How quickly can a WordPress vulnerability be exploited?

Patchstack reported a weighted median of five hours from disclosure to first observed exploitation among its prioritized subset of heavily exploited vulnerabilities in its analysis of 2025 flaws. It also said approximately half of the high-impact flaws in that analysis were exploited within 24 hours. These are provider-specific observations about a selected group, not a prediction that every vulnerability will be exploited on that schedule.

The practical implication is to treat security updates as time-sensitive, especially when a release addresses a vulnerability affecting software installed on your site. A vulnerability’s existence alone does not prove that your site is exposed: the affected product and version, configuration, and any required access or conditions matter.

What are the most common WordPress vulnerabilities?

The figures available here do not establish a ranked list of the most common vulnerability types across WordPress sites. Wordfence and Patchstack report vulnerability counts using their own datasets and classifications, but those totals do not by themselves show which flaw classes most often lead to successful compromises. Avoid treating the largest count as a ranking of the risks to your particular site.

One concrete warning comes from the Canadian Centre for Cyber Security: its July 2026 advisory said WordPress vulnerabilities CVE-2026-60137 and CVE-2026-63030 were being exploited in the wild. The advisory listed WordPress 7.0 before 7.0.2, 6.9 before 6.9.5, and 6.8 before 6.8.6 as affected, and said CISA added both vulnerabilities to its Known Exploited Vulnerabilities catalog on July 21, 2026. Those are historical remediation versions from that advisory, not a substitute for checking your installed version and current release notices. See the Canadian Centre for Cyber Security advisory for its scope and details.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to reduce the risk to a WordPress site

Security maintenance is a set of complementary controls, not a single product or setting. WordPress.org says only the latest WordPress version is officially supported; it notes that fixes have historically been backported to older releases as a courtesy. Keep the software you actually use current and be prepared to act when a relevant security update is released.

  1. Update core, plugins, and themes. Review installed software, apply current releases promptly, and remove components you no longer use. Confirm that an update applies to your installed product and version.
  2. Protect privileged logins with MFA. WordPress core does not include two-factor authentication. The administrator handbook recommends configuring it through a suitable plugin or identity provider; it also identifies a hardware key as an option. Verify compatibility and account-recovery arrangements before relying on a particular method.
  3. Use prevention and detection together. Consider a firewall and malware scanner, then monitor their alerts and site changes. A blocked request is useful protection telemetry, but it is not proof that a site is clean.
  4. Prepare to recover. Keep usable backups and a recovery plan so you know how to restore the site and regain administrative access if a compromise occurs.

The WordPress administrator handbook states: “Enable two‑factor authentication (2FA) for all administrator accounts (use a plugin or your identity provider; WordPress core does not include 2FA).” Read its guidance on brute-force attacks and account protection. WordPress’s security team also described a Core Security Initiative in August 2026 focused on a tighter, more automated release process, addressing the report backlog, and using AI-assisted scanning to find vulnerabilities before exploitation. Its security team page includes the initiative and disclosure guidance.

How many WordPress sites get hacked?

These sources do not establish a universal number or percentage of WordPress sites successfully compromised. Wordfence’s malware figure covers sites in its protected population; its blocked-attack figures count vendor telemetry. Patchstack’s figures count vulnerabilities and selected exploitation observations. None is a census of all WordPress websites or a comparable global breach rate.

Use the numbers to understand the kinds of risk being measured, not to infer a total number of victims. For an individual site, the actionable questions are whether its installed software is affected, whether it is patched, whether privileged accounts are protected, and whether monitoring and recovery are ready.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.