Skip to main content

Your website was fine on Monday. By Tuesday lunchtime it was serving malware to your customers.

Nothing changed at your end. You did not click a dodgy link. Nobody guessed your password. A plugin you have run happily for three years had a flaw nobody knew about, somebody found it, and automated scanners got to your site before your developer got to their inbox.

That is a zero-day hack. In security circles it is called a zero-day, because you get zero days of warning. And it has become the defining website security risk of 2026.

Attackers have levelled up

The old advice was reassuring in its simplicity. Keep WordPress updated. Keep your plugins updated. You will be fine.

It no longer holds up, and the numbers are blunt about why.

In 2025, 11,334 new WordPress vulnerabilities were disclosed, a 42 percent jump on the year before. Ninety-one percent of them were in plugins rather than WordPress itself.

Here is the part that should change how you think about this. At the moment those flaws became public knowledge, 46 percent had no fix available from the developer. Not a slow fix. No fix. Nearly half the time, the alarm goes off and there is nothing to install.

Meanwhile, attackers have got faster. For heavily targeted vulnerabilities, the median time from public disclosure to mass exploitation is now five hours. Around half of the high-impact ones are being exploited within a single day.

Five hours. That is less time than it takes most businesses to notice an email.

Your biggest risk is a plugin you have never thought about

Open your WordPress admin and count the plugins. Most business sites are running more than a dozen. Contact forms. Booking systems. Image galleries. A slider somebody installed in 2019 and forgot.

Each one is code written by a third party, running inside your website, with access to your database. Many are maintained by a single volunteer with no security budget and no obligation to keep going.

This is why the plugin numbers look the way they do. And it is why paying for a premium plugin is not the safety net people assume. In 2025, premium and freemium components produced 33 critical zero-day vulnerabilities against 12 in free components, and known exploited vulnerabilities turned up in premium plugins at roughly three times the rate.

You are not buying safety. You are buying features.

The attack has moved upstream

The newest problem is nastier again, because it bypasses everything you were told to do.

In June 2026, attackers compromised the update infrastructure of a WordPress plugin vendor called ShapedPlugin. Customers of three of its premium plugins downloaded an official update, from the official source, and installed a backdoor.

The malware sat quietly on every admin page load. It captured logins and two-factor codes in plain text, pulled out configuration files, administrator accounts and WooCommerce order data, disguised itself as a fake "WooCommerce Subscription" plugin so it would survive a cleanup, then deleted itself to make the investigation harder.

Doing the right thing was the attack. That is the shift worth sitting with.

AI has changed the economics of finding holes

Until recently, discovering a genuinely new vulnerability took a skilled researcher real time. That cost was the only thing keeping the volume down.

In May 2026, researchers from TrendAI and CHT Security presented work at Ekoparty Miami showing an automated pipeline that found more than 300 critical zero-day vulnerabilities in WordPress plugins in 72 hours. Average cost, based on the AI tokens consumed, was around 20 US dollars per vulnerability.

The researcher's own summary is the line to remember. In his words, "we are already in a state where any motivated attacker with a credit card can execute this."

New Zealand businesses are squarely in the blast radius

It is tempting to file this under things that happen to big American companies.

Research published by the National Cyber Security Centre on 21 September 2026 says otherwise. Fifty-three percent of New Zealand SMEs experienced a cyber threat or attack in the preceding six months. For businesses with 20 to 49 staff, that figure was 76 percent. More than three quarters.

Forty-three percent of SMEs now believe they are vulnerable, up from 34 percent a year ago, and thirty-two percent do no cyber security training with their staff at all.

NCSC Acting Deputy Director-General Kevin Moar put the cause plainly: "AI is making it easier for cyber criminals to carry out attacks, and to increase the effectiveness of those attacks."

So what actually protects you now

If updates alone cannot save you, what does? Five things, in order of how much they matter.

Wordpress hardening. The process of securing and tightening a WordPress website's configuration, code, and server environment to reduce its attack surface and make it much harder for hackers or malicious bots to compromise.

Virtual patching at the server. Having a firewall such as Cloudflare or AWS WAF which can block attempts on unpatched sites at the request level, before it reaches your server.

A plugin diet. Every plugin is a door. Audit what you are running, remove anything you do not actively use, and replace abandoned plugins before they become somebody's entry point.

Having a data recovery plan. Even with all measures in place, WordPress sites can still get hacked. A data recovery plan needs to include clean backups and a tested rollback plan is paramount.

Monitoring that tells you fast. Plenty of owners find out they have been compromised when a customer emails or Google flags the site in search results. File integrity monitoring and uptime alerts turn a three-week disaster into a two-hour inconvenience.

None of this is exotic. It is just maintenance that somebody has to own, on purpose, regularly.

The question worth asking this week

Not "is our website secure?" Nobody can answer that honestly.

Ask this instead: if a critical flaw in one of our plugins went public at 9am tomorrow, who would know, and how long would it take us to be protected?

If the honest answer is nobody and no idea, that is not a technology problem. It is a gap in who owns the site once it goes live, and it is fixable in an afternoon.

At hairyLemon we build and host websites for New Zealand businesses, and we handle server security as part of hosting, recommend WAF, and handle updates, added protection and hardening. If you would like a straight answer on where your site currently sits, our audits cover security alongside performance, accessibility, SEO and UX, and give you a prioritised list of actions to implement.

Talk to us about Hosting & Security

Back to all insights

Share this article on

Categories