I have spent 35 years watching the same infrastructure decisions go wrong, and the WordPress security picture in 2026 is the worst I have seen it. Not because WordPress is bad. Because the economics around it have quietly broken, and most business owners in Brisbane have no idea they are standing on the fault line.
This is written for you, the owner. Not your developer. If you have a WordPress site, a hosting invoice you do not fully understand, and a vague feeling that “someone is looking after it”, read on. The point of this article is to replace that vague feeling with three questions you can ask this week.
The numbers, in business terms
Start with the cost. The Australian Signals Directorate’s latest Annual Cyber Threat Report puts the average self-reported cost of a cybercrime incident for a small business at $56,600, up 14% on the year before. For medium businesses it is $97,200. ASD received a cybercrime report every six minutes. That is not a large-enterprise problem. That is a Fortitude Valley cafe with an online booking form.
Now the supply side. Patchstack’s State of WordPress Security in 2026 report counted 11,334 new WordPress vulnerabilities in 2025, a 42% jump on the previous year. Ninety-one percent of them were in plugins, not WordPress itself. Nearly half, 46%, had no fix available when they were publicly disclosed. And for the ones attackers cared about, the median time from disclosure to first exploit was five hours.
Five hours. Your developer checks the site monthly. Your host emails you at renewal. The attacker is running a script that checks every WordPress site on the internet by lunchtime.
One more figure from the same report, because it matters for the hosting conversation below: when Patchstack measured how much WordPress-specific attack traffic was blocked by conventional hosting defences, the answer was 12%.
What I am seeing in the field
I run a fleet of WordPress sites for Australian businesses and I handle compromises for people who are not yet clients. Three patterns dominate right now.
The abandoned plugin. Your site was built in 2021 by a developer who has since moved on. It runs 30 plugins. Six of them have not been updated by their authors in two years. Nobody is watching them, including the people who wrote them. This is the single most common way I see small business sites fall over, and it is invisible from the front end. The site looks fine right up until it is a phishing page for a bank.
The routine action that becomes the attack. Earlier this month Wordfence disclosed a flaw in All-in-One WP Migration and Backup, a plugin on more than five million sites. An attacker plants a payload through a trackback (a feature almost nobody uses and almost nobody has turned off), and it detonates when an administrator does something completely normal: a backup or a restore. A fix shipped on 20 August 2026. At disclosure, roughly 65% of installs, about 3.25 million sites, had not applied it. Ask yourself who on your team would have known.
The site that is not the target. In August, Check Point Research unmasked an operation called StopAndProtect that had quietly turned nearly 2,000 hacked WordPress sites into criminal infrastructure: malware hosting, command-and-control, and storage for data stolen from victims’ computers. The way in was mundane. Outdated WordPress installs, some from 2021, and unpatched plugins. The owners of those sites were not hacked because anyone wanted their data. They were hacked because their server was free, had a clean reputation, and nobody was looking.
That last one is the shape of the 2026 threat. Your site does not have to be interesting. It just has to be available.
Why cheap hosting makes this worse
Here is the uncomfortable part of the hosting conversation.
Most Australian small business sites sit on shared cPanel hosting bought for the price of a coffee a month. I understand why. It works, mostly, and the alternative sounded like a sales pitch.
But shared hosting is a shared fate. You are on a server with hundreds of other sites, one of which is the abandoned 2021 build I described above. When it gets compromised, your IP reputation goes with it. Your email starts bouncing. Google flags the neighbourhood. And the hosting company’s security, as Patchstack measured, is stopping about one attack in eight.
Cheap hosting also comes with a cheap support model. “Managed” on a $5 plan means they manage the server, not your WordPress. Nobody is updating your plugins. Nobody is reading the vulnerability feeds. Nobody is checking whether your backup can actually be restored, which, after 35 years, I can tell you is the difference between a bad day and a closed business.
Ey3 does it differently, and I will describe the outcome rather than the recipe, because publishing your defences is its own kind of mistake. Your site gets its own server in Sydney, not a shared one. Nothing reaches that server without passing through a filter that has already seen most of today’s attacks somewhere else in the world. Your backups exist in three copies, in two different places, one of them off-site, encrypted and out of reach of anyone who gets into the site itself. And we restore from them on purpose, on a schedule, so the first time we test the backup is not the day you need it.
When I handle a compromise, the first two questions are always “who else was on that server?” and “what was in front of it?”. I built our hosting so the answers are “nobody” and “something that stopped this yesterday”.
The regulatory clock is also running
If your business handles personal information and turns over more than $3 million, or is in a covered category, you are an APP entity under the Privacy Act. From 10 December 2026, new transparency obligations for automated decision-making take effect, and the OAIC has signalled it will read them broadly. For covered entities, a compromised website that leaks a customer list is already a notifiable data breach if serious harm is likely. The regulatory cost of a hack has been rising for two years and it takes another step up in December.
I wrote about what this means for mid-market firms in What a Fractional CTO Actually Is. For smaller businesses the short version is: a hacked site is no longer just an IT embarrassment. It is a compliance event.
Three questions to ask this week
You do not need to understand any of the technology to find out where you stand. Ask whoever looks after your site these three questions and listen to the shape of the answer.
1. “When was the last time we restored the site from backup, and did it work?” If the answer contains the word “should”, you do not have a backup. You have a subscription.
2. “How many of our plugins have not been updated by their author in the last twelve months?” If they cannot tell you within a day, nobody is looking. The correct answer is a number, and a plan for each one.
3. “What sits in front of the site, and what did it block last week?” If the answer is “the hosting company handles that”, refer to the 12% figure above.
A competent provider will answer all three without flinching. A poor one will change the subject to how good the site looks.
What Ey3 does about it
We have been building websites since 1996 and defending them for most of that time. Our approach is not clever. It is consistent.
A Security Audit ($600 inc. GST) answers the three questions above and about twenty more, in plain English, with a ranked fix list. If you are already compromised, Malware Cleanup ($260 inc. GST) gets you clean and tells you how they got in. For ongoing cover, the Monthly Maintenance Ultimate Pack (from $70 inc. GST per month) means a human in Brisbane is reading the vulnerability feeds so you do not have to. And if you want out of the shared-hosting neighbourhood, WordPress Hosting Australia puts your site on its own Sydney server with the protection described above from $30 inc. GST per month, with the Expert Transfer Mega Pack handling the move.
You can browse the full range under Security, Maintenance and Hosting.
Or just call 1300 856 393. Tell us what your current provider said when you asked the three questions. We will tell you honestly whether you have a problem, and we will not pretend you do if you don’t.
Frequently asked questions
Is WordPress itself insecure?
No. WordPress core accounted for six of the 11,334 vulnerabilities Patchstack recorded in 2025. The risk is in the plugin ecosystem and in sites nobody maintains. A well-hosted, well-maintained WordPress site is as secure as anything else on the web.
My site is small. Why would anyone attack it?
Because attackers do not choose. They scan every WordPress site on the internet for known flaws and take whatever answers. Small sites are then used as infrastructure to attack others, as the StopAndProtect operation showed. Your size is not a defence; your patch status is.
How quickly do I need to apply plugin updates?
For serious vulnerabilities, within hours, not weeks. The median time to first exploit for heavily targeted flaws is about five hours after disclosure. This is why a web application firewall matters: it buys you time when a patch is not yet available or applied.
What is the difference between “managed hosting” and what Ey3 offers?
Most “managed” shared hosting manages the server. It does not update your plugins, monitor vulnerability disclosures, test your backups or filter attacks aimed at WordPress. Ey3’s hosting and maintenance packs do all of that: your own Sydney server, layered filtering in front of it, backups kept in three copies across two locations with one off-site, and restores tested on a schedule. With a Brisbane team you can ring.
Do I have legal obligations if my website is hacked?
If your business is covered by the Privacy Act and the breach is likely to cause serious harm, you must notify the OAIC and affected individuals under the Notifiable Data Breaches scheme. New automated decision-making transparency rules also commence on 10 December 2026. When in doubt, seek legal advice; we can help with the technical side of the assessment.
Sources: Australian Signals Directorate, Annual Cyber Threat Report 2024–25; Patchstack, State of WordPress Security in 2026; Check Point Research, “Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect”, 19 August 2026; Wordfence disclosure of CVE-2026-19949 (All-in-One WP Migration and Backup), September 2026; OAIC, consultation on guidance for transparency in automated decision-making.