WordPress security series · Part 1 of 6
Five hours. For the WordPress vulnerabilities attackers care most about, that is the median time between the flaw going public and the first attack, according to Patchstack’s State of WordPress Security in 2026 report.
Now compare that with how most business websites are looked after. A developer logs in once a month. The host sends an email at renewal. Someone updates plugins when they remember.
That gap is where small businesses get hurt.
What the gap costs
The Australian Signals Directorate’s Annual Cyber Threat Report puts the average self-reported cost of cybercrime at $56,600 for a small business and $97,200 for a medium one. For plenty of Brisbane businesses, that is the year’s profit.
The volume is climbing too. Patchstack counted 11,334 new WordPress vulnerabilities in 2025, up 42% on the year before. Ninety-one percent were in plugins. Nearly half had no fix available on the day they went public.
What good looks like
The Essential Eight, the Australian Government’s baseline for cyber security, says internet-facing services should be patched within two weeks, or within 48 hours if an exploit exists. Your website is an internet-facing service. Most small business sites I look at miss both targets by months.
Closing the gap
You do not need to become a security expert. You need three things in place:
- Someone checking for new plugin flaws daily, not monthly.
- Updates applied within 48 hours when a flaw is being actively attacked.
- Protection in front of the site that can block an attack before a fix exists.
If you cannot name who does each of those for your site, nobody does.
The question to ask this week
“If a plugin on our site had a serious flaw announced this morning, when would it be fixed?”
If the answer is “at the next monthly update”, you are a month behind a five-hour problem.
Next step
Our monthly maintenance plan (from $70 inc GST per month) puts a Brisbane team on watch every day. Browse our other security services, or call 1300 856 393 and we will tell you where you stand.
Common questions
What is a WordPress vulnerability?
Are automatic updates enough?
How often should my website be checked?
The six-part series
- Five Hours: The Gap Between a WordPress Flaw and an Attack — you are here
- Abandoned Plugins: The WordPress Risk You Can’t See (29 September)
- When Your Backup Plugin Becomes the Way In (6 October)
- Your Website Isn’t the Target. It’s the Tool. (13 October)
- Cheap Hosting Is a Shared Fate (20 October)
- A Hacked Website Is Now a Compliance Problem (27 October)
Based on the full article: Your WordPress Site Is Probably Already a Problem.