Last lesson: what a hack costs. Now: how break-ins actually happen — because once you see the mechanism, the fix makes sense.
When a serious hole in website software is made public, attacks typically begin within five hours.
It's the question almost every owner asks. And the answer surprises people: nobody's sitting in a basement targeting you personally. The truth is less personal — and more useful — than that.
Automated bots crawl the web around the clock, checking millions of sites for known holes in WordPress, plugins, and themes. They don't know you. They don't care what you sell. When they find a site with a known hole, the attack just… runs. No human needed.
Hackers don't choose small businesses — bots find them. Because small businesses are the ones running outdated software. The most common way in isn't clever. It's an open door that already had a patch.
A bot scans millions of sites for known holes
It finds one site running outdated software — any site
The attack runs itself — no human, no choice, no mercy
In 2025, researchers found over 11,000 new vulnerabilities in the WordPress world — 42% more than the year before. That number will keep growing. This is why "we updated last month" isn't a plan.
And here's the part almost nobody knows: it's not WordPress itself. The core software is well-guarded by a full-time security team. The holes turn up in plugins — the add-ons doing contact forms, SEO, caching, page-building. Every plugin you add is extra code with deep access to your site. That's where the doors are.
Every plugin = extra code with deep access. That's where the doors are.
Outdated plugins are one way in. A guessed or stolen password is the other. Bots try millions of common passwords a day — and reusing a password from another site means one leak anywhere hands over your website. The fix is yours to make, today: a long, unique password (three unrelated words beats one clever one) and two-factor login if your platform offers it. Unlike plugins, this door never needs a developer — you can lock it tonight.
Three words you won't forget. One code you don't reuse. Done.
A researcher publishes a serious plugin flaw
Bots start exploiting it — median time, across all 2025 disclosures
Mass scanning: every site running that plugin gets hit
Often before the developer has even finished the patch. If you update weekly, you're statistically updating after the attack wave passed.
About 36 new WordPress plugin vulnerabilities come out every day. And nearly half of them ship with no fix available at all yet. A person reading update alerts and clicking "update" can't beat that. Nobody's willpower can.
About a week — there's time to get to it on the weekend
The 5-hour median kills the "weekend update" plan — half of all exploited flaws are attacked within 24 hours of going public.Within hours — the median is around 5 hours
Correct. Attackers scan the moment a flaw is public. This is why real-time monitoring and fast patching beat a weekly update habit.Weeks — vendors notify everyone first
Vendors need time to write patches; bots don't wait for them. Disclosure and exploitation are nearly simultaneous now.Only if your site is famous or high-traffic
Mass scanning hits every exposed site running the plugin. Traffic doesn't protect you — the bots don't check your visitor count first.Updates have to happen, and they have to be fast — but they also have to be safe. Here's the loop, every single time:
on a staging copy — a full clone of your site
before touching the real site
to the live site
forms, pages, features all working
Skip the testing, and an update can silently break a form for weeks. Skip the backup, and there's no way back. This loop is the whole trick — and it's what we do at WebsiteCare.Direct every single time.
That's the machine-level threat — and why updates can't be a once-a-month chore. You've also locked the third door tonight: your login. Next lesson, the other big way in: your inbox. That test-then-apply loop in this lesson? It's our entire update process, running on your site, every time. 24/7 monitoring, staging-tested updates, daily tested backups — from $49/month, month-to-month, no contract.