Why WordPress Websites Get Hacked

Why WordPress Websites Get Hacked

WordPress powers websites for everyone from one-person businesses to large organisations. That popularity makes it incredibly useful, but it also makes WordPress websites an attractive target for cybercriminals.

There is a common misconception that hackers only go after large companies with valuable customer databases. In reality, many attacks aren’t personally targeted at all.

Automated bots continuously scan the internet looking for WordPress websites with known weaknesses. They don’t particularly care whether you run a national retailer or a small plumbing business in North London. If the door is open, they’ll give it a push.

So, why do WordPress websites get hacked?

1. Outdated plugins

Plugins are one of WordPress’s biggest strengths. They allow businesses to add everything from contact forms and online booking to e-commerce and SEO tools.

But every plugin is also additional software that needs maintaining.

When a vulnerability is discovered, a reputable plugin developer will normally release an update to fix it. Once details of that vulnerability become known, attackers can start looking for websites still running the older version.

This is why leaving plugin updates sitting in the dashboard for months isn’t a great idea.

The same applies to abandoned plugins. If the developer has stopped maintaining one, there may eventually be nobody fixing newly discovered security problems.

2. WordPress and themes aren't kept updated

It’s not just plugins.

WordPress itself and installed themes should also be kept up to date. Security fixes are regularly included alongside bug fixes and improvements.

Businesses sometimes avoid updates because they’re worried something might break. That’s understandable, particularly when the website is generating leads or sales.

The solution, however, isn’t to stop updating indefinitely. It’s to have a proper update process with reliable backups and testing where appropriate.

3. Weak or reused passwords

A password such as your business name followed by 123 isn’t putting up much of a fight.

Automated login attacks can try large numbers of username and password combinations. Credentials exposed through breaches elsewhere can also be tested against other websites.

This is particularly dangerous when somebody has reused the same password across several services.

WordPress administrator accounts should use strong, unique passwords. Adding two-factor authentication provides another layer of protection if a password is compromised.

4. Too many administrator accounts

This one is easily overlooked.

A website that’s been running for several years may have had different developers, marketing agencies, employees and freelancers working on it.

Have a look under Users in your WordPress dashboard.

Does everybody with administrator access still need it?

Old accounts should be removed when they’re no longer required, and users shouldn’t have administrator privileges simply because it’s convenient. Give people the level of access they actually need.

5. Poor hosting security

You can do everything correctly inside WordPress and still have weaknesses elsewhere.

Your hosting account, PHP version, database, file permissions, SSL configuration and hosting control panel are all part of the wider security picture.

Cheap hosting isn’t automatically insecure, and expensive hosting isn’t automatically secure. What matters is whether the environment is properly maintained and supported.

Your hosting control panel also deserves a strong password and two-factor authentication where available.

6. Malware can arrive through legitimate-looking files

Not every compromise begins with somebody attacking the WordPress login page.

Malicious code can arrive through compromised plugins, themes, infected computers, stolen credentials or files obtained from untrustworthy sources.

Be particularly careful with “nulled” premium WordPress themes and plugins downloaded from unofficial websites. Saving a few quid on a plugin isn’t much of a bargain if you’ve also installed somebody else’s malicious code.

7. There's no security monitoring

Some compromised websites immediately display obvious signs that something is wrong.

Others don’t.

An attacker may want to remain unnoticed while redirecting selected visitors, creating spam pages, stealing information or using the website for another purpose.

That means simply visiting your homepage occasionally isn’t a security check.

Monitoring file changes, failed login attempts, new administrator accounts and other unusual activity can help identify problems that might otherwise sit unnoticed.

Can you stop a WordPress website ever being hacked?

Nobody can responsibly guarantee that a website will never be compromised.

What you can do is make it considerably harder.

Think of WordPress security as several layers rather than one magic security plugin. Keep WordPress, plugins and themes updated. Remove software and accounts you don’t need. Use strong passwords and two-factor authentication. Maintain proper off-site backups. Keep the hosting environment secure and monitor for suspicious activity.

Most importantly, don’t wait until something goes wrong before looking at security.

If your business depends on its website for enquiries, bookings, sales or communicating with customers, it’s worth treating the website as a business system rather than something that was built five years ago and left sitting on the internet.

A little preventative work now can save a considerably bigger headache later.

Gtec Media provides WordPress website hardening and security support for businesses, helping identify weaknesses and put practical security measures in place before they become a problem.