WordPress Plugin Vulnerabilities: Why 96% of the Risk Lives in Your Add-ons

The WordPress core software is remarkably solid, so the real danger to your small-business website almost always comes from the plugins and themes you bolt on top of it.

By Nathan Cross, Co-Founder, Network & Security Engineering·

The number that should change how you think about WordPress

If you run a small-business website on WordPress, here is the single most useful fact to keep in mind about WordPress plugin vulnerabilities: plugins account for roughly 96% of WordPress vulnerabilities, and only a handful are ever found in WordPress core itself (Patchstack). In plain terms, the WordPress software you started with is rarely the weak point. The weak point is the collection of contact forms, booking calendars, page builders, SEO tools, and gallery plugins you added afterward.

That matters because it tells you exactly where to spend your limited time and attention. You do not need to become a security expert or rebuild your site. You need a sensible routine for the add-ons, because that is where the attackers are looking.

Why WordPress plugin vulnerabilities are the favourite way in

WordPress core is maintained by a large, professional team that reviews code carefully and ships security fixes quickly. Plugins and themes are a different world. Anyone can write one, and the WordPress plugin directory alone holds tens of thousands of them, written by everyone from full-time companies to weekend hobbyists.

The volume of new flaws is staggering and still climbing. Patchstack recorded nearly 8,000 new WordPress vulnerabilities in 2024, about a 34% increase on the year before (Patchstack, via SecurityWeek). The vast majority of those live in plugins and themes, not in core.

Attackers like this for a simple reason: scale. A single popular plugin can be installed on hundreds of thousands of sites. Find one flaw in it, and you have a master key that opens the same door on every site running that version. They do not need to target your business by name. They scan the whole internet looking for that one vulnerable plugin.

Abandoned plugins: the quiet danger

The most dangerous plugin on your site is often one you have completely forgotten about. A plugin becomes abandoned when its author stops releasing updates, sometimes because they moved on, sold the project, or simply lost interest.

An abandoned plugin still works, so nothing on your site looks broken. But when a new vulnerability is discovered in it, there is no one left to write a fix. The hole stays open indefinitely, and your site keeps running the flawed code month after month.

This is why a plugin you installed years ago for a one-time job, and never thought about since, can quietly become your biggest liability. If the WordPress directory shows a plugin has not been updated in over a year, or warns that it is no longer maintained, treat that as a red flag to replace or remove it.

How attackers know which version you are running

You might assume your plugins are a private detail, but many of them announce themselves to the outside world. This is called version fingerprinting, and it is easier than most owners realise.

Plugins frequently leave clues in plain sight: a version number in a CSS or JavaScript file path, a comment in your page's source code, a readme file left in a public folder, or a distinctive URL pattern. Automated tools read these clues, match them against public databases of known vulnerabilities, and build a target list in seconds.

This is exactly the gap a good security check is meant to close. A passive external scan like BadgerScan reads the same publicly visible clues an attacker would and flags any detectable versions with known issues. The catch is that the outside view can only see what is exposed publicly. To know the exact version of every plugin, theme, and the core itself, you have to look from the inside, which is what our read-only WordPress plugin does on the Pro plan. Combining both views is the only way to get the full picture in one place.

A simple plugin hygiene routine

You do not need a complicated security programme. You need a short, repeatable habit. Here is a routine any small-business owner can follow, no technical background required.

  • Inventory everything. List every plugin and theme on your site, including the ones you are not actively using. You cannot protect what you have forgotten about.
  • Update on a schedule. Apply plugin, theme, and core updates at least weekly. Most vulnerabilities are fixed by the author before attackers exploit them widely, so the fix only helps if you actually install it.
  • Delete, do not just deactivate. A deactivated plugin still has its code sitting on your server, where a flaw can sometimes still be reached. If you are not using it, remove it completely.
  • Check for abandonment. Twice a year, look up each plugin and confirm it is still maintained. Replace anything that has gone quiet for a year or more.
  • Back up before you change anything. Keep a recent, tested backup so an update that goes wrong is an inconvenience, not a disaster.
  • Turn on automatic updates for trusted plugins. For well-maintained add-ons from reputable authors, automatic updates close the gap between a fix being released and you installing it.

Why this matters more for small businesses

It is tempting to assume attackers only care about big companies, but the data points the other way. In Verizon's 2025 Data Breach Investigations Report, ransomware or extortion appeared in 88% of breaches at small and medium businesses, versus 39% at larger organizations (Verizon 2025 DBIR).

Small businesses are attractive precisely because they tend to have fewer defences and less time to maintain them. A neglected plugin on a local business website is a soft target. The good news is that the fix is almost entirely within your control: keep your add-ons current, remove what you do not need, and check your site from both the outside and the inside so nothing slips through.

See which of your plugins are putting you at risk

Run a free BadgerScan to check your site from the outside in minutes, no signup required. Want the full picture, including the exact version and known issues for every plugin, theme, and the core itself? Upgrade to Pro for C$10/mo per site and our read-only plugin scans the inside too, combining everything into one plain-English grade and one prioritised fix-list. If you would rather hand it off, our Hamilton and Burlington team can do the fixing for you. Call (289) 796-8900.

Run a free security scan

Frequently asked questions

If WordPress core is so secure, do I still need to update it?

Yes. Core updates are still important and often include their own security and stability fixes. The point is not that core never needs attention, it is that the bulk of the real-world risk, roughly 96% of vulnerabilities, comes from plugins and themes (Patchstack), so that is where the most careful, frequent attention belongs.

How can I tell if a plugin has been abandoned?

Open the plugin's page in the WordPress.org directory and look at the 'last updated' date and the 'tested up to' WordPress version. If it has not been updated in over a year, or the directory warns it is no longer maintained, treat it as abandoned and plan to replace or remove it.

Is it safe to just deactivate a plugin instead of deleting it?

Deactivating is not enough. The plugin's code still sits on your server, and in some cases a vulnerability in inactive code can still be reached. If you are not actively using a plugin, delete it completely. You can always reinstall it later if you need it again.

Can a free scan actually find plugin vulnerabilities?

A passive external scan like BadgerScan can detect any plugin and version that is exposed publicly and match it against known vulnerabilities, which catches a lot. To see the exact version of every plugin, theme, and the core, you need an inside view too. Our Pro plan adds a read-only WordPress plugin and fuses the inside and outside results into one grade and one fix-list.

Keep reading

Sources

  1. Patchstack, State of WordPress Security
  2. SecurityWeek, 8,000 New WordPress Vulnerabilities Reported in 2024
  3. Verizon, 2025 Data Breach Investigations Report

More from CyberBadger

BadgerScan is the website side of what we do. We're one local Hamilton and Burlington team for your whole setup, on-site nearby and remote across Canada.

Coming soon: BadgerAudit. A full, on-site cybersecurity audit, interviews, hands-on review, and a detailed report, for when a self-serve scan isn't enough. Ask us about it.