Most company websites get built the same way: a project, a launch, an invoice — then silence. The site works, so nobody touches it. Often nobody remembers the login. For years, that never mattered.
This year it did. WordPress — the software behind roughly 43% of all websites (W3Techs), quite possibly including yours — was hit by three waves of mass compromise in four months. The sites that got hurt were, overwhelmingly, the ones nobody was looking after.
2026 so far, in three waves.
April — the updates were poisoned
Attackers compromised more than 25 plugins on WordPress.org — the official directory — and hid backdoors inside legitimate-looking updates. Around 800,000 sites were exposed. The uncomfortable part: these owners did the right thing. They kept their plugins updated, and the update was the attack.
June — six holes at once
Six separate plugin flaws, each rated 9.8 out of 10 for severity, all under attack at the same time — around 1.14 million sites, tens of thousands of attack attempts logged daily. The plugins were nothing exotic: a theme customiser, a caching tool. What a normal small-business site runs.
July — WordPress itself
Researchers named it wp2shell: two core flaws that chain into full takeover of a default installation — no plugin, no theme, no password (CVE-2026-63030 and CVE-2026-60137, for the record). Attack scripts went public within days; on 21 July the US cyber agency CISA confirmed active exploitation. WordPress patched fast and pushed forced updates — good response — but forced updates only reach sites still receiving them. A site nobody has logged into for years may not be.
It is not that WordPress is bad. It is that nobody is watching.
Blaming the software misses what decides the outcome. WordPress earned its share of the web by being capable and free, and in maintained hands it came through 2026 fine.
But a WordPress site is a running computer program: code executing on a server, a database behind it, an admin login on the public internet, and typically a dozen plugins by a dozen authors on a dozen schedules. Parts like that develop holes continuously — security trackers have logged over 250 new plugin vulnerabilities in a single week this year, roughly 43% of them usable without logging in, a quarter still unpatched a month after disclosure.
That is manageable — routine, even — when watching it is somebody's job. This year's damage concentrated where nobody was watching anything: sites built once by a freelancer or an agency whose contract ended, then left running.
We have measured the local version. In our July study of 400 Malaysian electrical contractors, 77 had a live website we could inspect — and 7 were visibly degraded: homepage timeouts, obsolete technology, copyright lines frozen years ago. Abandonment is normal enough in this market that a visibly maintained site is a competitive signal on its own.
One fairness note, because we have made it before: WordPress dominating hacked-site cleanups is not a per-site risk rate — it also dominates the web. The defensible lesson is narrower: most compromises arrive through out-of-date components, and an unmaintained site accumulates risk every month it stands still.
Nobody is targeting you. That is the problem.
Owners of small sites assume they are too small to interest anyone. But nobody chooses your site. A scanner works through millions of addresses looking for one signature — a plugin version, an exposed endpoint — and compromises whatever answers. There is no list to be too small for. There is only whether your software has the hole.
And a hacked small-business site is rarely dramatic: pages quietly redirecting to scam sites, rankings evaporating once Google flags the domain, the hosting account sending spam until it is suspended — or a webshell sitting dormant, holding the door open. The owner typically finds out from a customer, months in.
If you run WordPress, do these four things this week.
Check the version, then update
Log in to the admin panel. If WordPress is older than 6.9.5 (or 7.0.2 on the 7.x line), update now — that is the wp2shell patch — and switch automatic updates on. If nobody knows the login, treat that as the finding: your site has no operator.
Cut the plugin list down
Delete — not just deactivate — every plugin you do not use; deactivated code has been used in attacks before. A remaining plugin its author has not touched in over a year is abandoned, and abandoned plugins never get security fixes.
Look for signs someone is already in
Check the user list for administrators you do not recognise, and search your company name in Google to see whether results redirect somewhere strange. If you find either, do not clean up casually — attackers leave more than one way back in. We have written what to do first, in the right order.
Confirm a backup exists off the server
A backup on the same server dies with the site. Confirm one exists elsewhere, and that someone has actually restored from it once. A backup nobody has tested is a hope, not a backup.
None of this requires buying anything, from us or anyone. If it all checks out — current version, short plugin list, no strangers in the user table, tested backup — your site is in better shape than most, and you can stop reading here.
The other way to not have this problem.
Everything above is the running cost of a website that is software. There is a second architecture — the one this site is built on: static pages, assembled in advance, served finished. No code executing per visitor, no database, no plugins, no admin login to phish. The parts the entire 2026 attack wave came through do not exist.
Said honestly: not “unhackable” — distrust anyone who uses that word. The registrar account, DNS, email and whatever receives your contact form still need protecting, as on every website ever made. And the fit has limits: static suits sites that present a firm and change on request — most professional and trade businesses — not an online store, a booking system, or a client portal.
Our interest, declared: this is the arrangement we sell. Website Custody moves an existing WordPress site onto our static platform — the move quoted up front — then keeps it working for one annual fee, from RM600 a year, with every price and exclusion published. The most common site we take over is exactly the one this article describes: a WordPress build whose maintenance ended when the agency contract did. But the four checks above stand on their own — do them this week, whether or not you ever talk to us.
The unglamorous conclusion.
Every website is either maintained or abandoned; there is no third state, and 2026 has been a demonstration of what the internet does to the abandoned ones. A WordPress site with a real operator is fine — if that describes yours, this was never about you. Most small-firm sites, though, were built as a project and left as an orphan, on the architecture that punishes orphanhood hardest.
So the decision is not really “which platform.” It is: either give the software an owner, or own less software. Both answers are respectable. Only the current default — software with nobody watching it — is not.
Retrieved from https://amkatechnologies.com/insights/why-wordpress-sites-keep-getting-hacked
Published 29 July 2026 · last updated 30 July 2026. AMKA Technologies Sdn Bhd, SSM 202301041763 (1535682-T).