Five Hours: The Gap Between a WordPress Flaw and an Attack

WordPress security series · Part 1 of 6

Five hours. For the WordPress vulnerabilities attackers care most about, that is the median time between the flaw going public and the first attack, according to Patchstack’s State of WordPress Security in 2026 report.

Now compare that with how most business websites are looked after. A developer logs in once a month. The host sends an email at renewal. Someone updates plugins when they remember.

That gap is where small businesses get hurt.

What the gap costs

5 hours
median time from a flaw going public to the first attack
11,334
new WordPress vulnerabilities in 2025, up 42%
$56,600
average cost of a cybercrime incident for a small business

The Australian Signals Directorate’s Annual Cyber Threat Report puts the average self-reported cost of cybercrime at $56,600 for a small business and $97,200 for a medium one. For plenty of Brisbane businesses, that is the year’s profit.

The volume is climbing too. Patchstack counted 11,334 new WordPress vulnerabilities in 2025, up 42% on the year before. Ninety-one percent were in plugins. Nearly half had no fix available on the day they went public.

What good looks like

The Essential Eight, the Australian Government’s baseline for cyber security, says internet-facing services should be patched within two weeks, or within 48 hours if an exploit exists. Your website is an internet-facing service. Most small business sites I look at miss both targets by months.

Closing the gap

You do not need to become a security expert. You need three things in place:

  • Someone checking for new plugin flaws daily, not monthly.
  • Updates applied within 48 hours when a flaw is being actively attacked.
  • Protection in front of the site that can block an attack before a fix exists.

If you cannot name who does each of those for your site, nobody does.

The question to ask this week

“If a plugin on our site had a serious flaw announced this morning, when would it be fixed?”

If the answer is “at the next monthly update”, you are a month behind a five-hour problem.

Next step

Our monthly maintenance plan (from $70 inc GST per month) puts a Brisbane team on watch every day. Browse our other security services, or call 1300 856 393 and we will tell you where you stand.

Call 1300 856 393

Common questions

What is a WordPress vulnerability?
A flaw in WordPress, a theme or a plugin that lets an attacker do something they should not, such as log in as an administrator or plant malicious code. Most are found in plugins.
Are automatic updates enough?
They help, but they only work once a fix exists, and nearly half of disclosed flaws had no fix on day one. You also need protection that blocks attacks in the meantime, and someone checking that updates have not broken the site.
How often should my website be checked?
Daily for new vulnerabilities. Monthly checks are too slow when attacks start within hours.

The six-part series

  1. Five Hours: The Gap Between a WordPress Flaw and an Attack — you are here
  2. Abandoned Plugins: The WordPress Risk You Can’t See (29 September)
  3. When Your Backup Plugin Becomes the Way In (6 October)
  4. Your Website Isn’t the Target. It’s the Tool. (13 October)
  5. Cheap Hosting Is a Shared Fate (20 October)
  6. A Hacked Website Is Now a Compliance Problem (27 October)

Based on the full article: Your WordPress Site Is Probably Already a Problem.