WordPress Security: The Protections That Stop Attacks

WordPress Security: The Protection that Stops Attacks

Most WordPress hacks start with a vulnerable plugin, not a guessed password. This guide puts WordPress security protections in priority order: what to fix today, what to schedule this week, and what your hosting provider should handle at the server level. You’ll also see why updates alone leave gaps and how to catch a compromise before it costs you traffic or sales.

The best WordPress security protection is layered. Keep plugins, themes, and core updated. Delete anything you don’t use. Require two-factor authentication for every administrator, keep tested off-site backups, and host on infrastructure that blocks attacks at the server and application level. Of those layers, plugins deserve the most attention: in Patchstack’s State of WordPress Security in 2026, 91% of new vulnerabilities found in 2025 were in plugins, and 9% were in themes.

Work through the sections below from top to bottom. Each one is ordered by how much risk it removes for the time it takes.

Where WordPress Attacks Come From

Patchstack counted 11,334 new vulnerabilities in the WordPress ecosystem in 2025, a 42% increase over 2024 (Patchstack). Only six of those were in WordPress core, and all six were low priority. The rest came from the plugins and themes you install.

Paid components are not automatically safer. Patchstack found three times as many known exploited vulnerabilities in premium plugins and themes as in free ones, partly because fewer researchers can access premium code to review it (Patchstack). That surprises a lot of site owners who assume a license fee buys better security.

Core still needs attention. In July 2026, researchers disclosed “wp2shell,” two WordPress core flaws that chained together to allow unauthenticated remote code execution on default installations running versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1 (Rapid7). WordPress released versions 6.8.6, 6.9.5, and 7.0.2 and forced automatic updates for compatible sites (INCIBE-CERT). Sites that had disabled core auto-updates stayed exposed longest. Our wp2shell compromise and recovery case study walks through what that looked like on a real site.

What To Do Today to Secure Your WordPress

These four steps take under an hour on most sites and close the gaps attackers hit most often.

Turn On Automatic Updates

Open Dashboard > Updates and install everything pending. Then go to Plugins and click Enable auto-updates next to each plugin you trust to update unattended. WordPress applies minor core releases automatically by default, so confirm nothing has switched that off, such as a WP_AUTO_UPDATE_CORE constant set to false in wp-config.php.

For WooCommerce stores or heavily customized sites, test major plugin updates on a staging copy first. Our roundup of WordPress staging plugins covers the options.

Delete Plugins and Themes You Don’t Use

Deactivating a plugin does not remove its files. Vulnerable code can still sit on the server, so delete anything inactive. Keep one current default theme as a fallback and remove the rest.

On WordPress.org, a warning appears on any plugin that hasn’t been tested with the last three major WordPress releases. Treat that warning as a reason to look for a maintained replacement.

Require Two-Factor Authentication for Every Admin

WordPress core does not include two-factor authentication, so you’ll need a plugin. Choose one that supports an authenticator app or passkeys and hardware security keys rather than relying on SMS or email codes. Text messages can be intercepted through SIM swapping, and email codes are only as secure as the inbox receiving them. See our comparison of the best two-factor authentication plugins for WordPress or follow the setup guide in our Support Center.

Update Your Password Rules

The old advice to mix uppercase letters, numbers, and symbols is out of date. NIST’s current authentication guideline, SP 800-63B-4, says systems shall not impose composition rules or require periodic password changes (NIST). It sets a 15-character minimum when a password is the only factor (Startup Defense).

In practice, that means:

  • Use a password manager and a unique password for every account
  • Choose 15 or more characters, or a passphrase of several unrelated words
  • Change passwords when there’s evidence of compromise, not on a calendar
  • Give every person their own login; never share one admin account

What You Should Do This Week

Audit User Accounts and Roles

Go to Users > All Users and remove former employees, contractors, and old agency accounts. Then check each remaining role:

RoleCan doWho should have it
AdministratorInstall plugins, change settings, manage usersOne or two people who maintain the site
EditorPublish and edit anyone’s contentContent leads, most clients on agency-built sites
AuthorPublish their own postsRegular writers
ContributorWrite drafts, no publishingGuest or occasional writers

Broken access control was the most exploited vulnerability type in 2025, and those exploits often look like normal logged-in traffic (Patchstack). If your site doesn’t need public registration, uncheck Anyone can register under Settings > General. Fewer accounts means fewer footholds.

Why Do Plugin Updates Need a Second Layer?

Updates only protect you once a fix exists. In 2025, 46% of WordPress vulnerabilities had no developer fix available when they were publicly disclosed (Patchstack). For the most heavily targeted vulnerabilities, the weighted median time from disclosure to first exploitation was five hours.

Attackers also keep working through old flaws. Of the ten most targeted vulnerabilities in 2025, only four were published that year (Patchstack). The other six were older bugs that sites still hadn’t patched.

So the gap is real on both ends. Some sites can’t patch fast enough, and some vulnerabilities have no patch to apply. Closing that gap takes protection that watches what code does, not just which version is installed.

What Should Your Hosting Provider Handle?

Some protections can’t be configured from the WordPress dashboard. They depend on how your host builds and runs its servers.

InMotion Hosting has worked with Monarx since 2021, and in the first year of that partnership we saw a 40% reduction in security-related support cases (InMotion Hosting). We’ve since deployed Monarx ThreatShield across our server fleet. A traditional firewall inspects a request before it reaches your application. ThreatShield runs inside the application runtime, so it evaluates what a request actually tries to do when it executes. That lets it stop:

  • Cross-site scripting and SQL injection
  • Remote code execution
  • Brute-force logins and credential stuffing
  • Spam and other application abuse

This matters most in the window between disclosure and patch, when your plugins are exposed and no update exists yet.

Your host should also patch server software, isolate accounts from one another, manage firewalls, and give you access to people who can help during an incident. InMotion Hosting support is available 24/7, and every technician completes more than 280 hours of training before handling Tier 1 cases.

For VPS and Dedicated Server customers who want malware defense and backups bundled together, InMotion Premier Care includes Monarx malware protection, backup storage, and expanded support access in one plan. You can also add Monarx Security on its own.

No single layer catches everything. Host-level protection reduces what reaches your site; it doesn’t replace updates, strong logins, or backups.

Does Changing the WordPress Login URL Improve Security?

A little. Moving /wp-admin cuts down automated login noise in your logs, but it doesn’t stop plugin exploits, which rarely touch the login page at all. Treat it as housekeeping, not protection. Some caching and security plugins also conflict with custom login paths, so test after changing it.

Which WordPress Security Plugin Should You Use?

One well-maintained security plugin is enough for most sites. Wordfence and similar tools handle login limiting, file-change alerts, and two-factor authentication in one place. Avoid running two firewall plugins at once. They conflict, double the processing on every request, and can push a shared hosting account into its CPU limits. Schedule full malware scans for low-traffic hours.

How Can You Catch a WordPress Compromise Early?

Modern WordPress malware is built to hide. Common campaigns show spam to search engine crawlers, redirect some human visitors to scam sites, and serve site owners a clean page (Patchstack and Monarx). One malware family, Lock360, runs in server memory and rewrites files like index.php and .htaccess as soon as they’re restored.

Watch for these signs:

  • Unfamiliar pages when you search site:yourdomain.com on Google
  • Customers reporting redirects you can’t reproduce
  • Administrator accounts nobody created
  • PHP files inside /wp-content/uploads/
  • Files that change back after you clean them

If you see any of them, contact support before restoring a backup, since a memory-resident infection can reinfect a clean restore. Our [Website Services team]([HACKED SITE REPAIR URL]) also offers hacked site repair with standard and priority turnaround.

Is Your WordPress Site Ready for the Holiday Attack Surge?

Monarx observed malicious file uploads nearly tripling in November and December 2025, as holiday traffic peaked and IT teams ran short-staffed (Patchstack and Monarx). For WooCommerce stores, that’s the worst possible timing.

Before Black Friday, work through the today and this-week lists above, freeze nonessential plugin installs, and confirm a backup restore works. Write down who to call if checkout breaks at 11 p.m. on a Saturday.

Where Should You Start?

PriorityTaskTime neededWho handles it
TodayUpdate everything, enable auto-updates15 minutesYou
TodayDelete unused plugins and themes10 minutesYou
TodayRequire two-factor authentication for admins20 minutesYou
This weekAudit users and roles30 minutesYou
This weekLimit logins, disable file editing20 minutesYou
This weekCheck PHP version, test a backup restore1 hourYou or your developer
OngoingRuntime protection, malware detection, server patchingContinuousYour host

If your current host leaves that last row to you, it’s worth a closer look. InMotion Hosting for WordPress runs on infrastructure we build and operate ourselves, with ThreatShield protection deployed across our fleet and real people on support around the clock. For agencies managing many client sites or stores that need dedicated resources, VPS Hosting for WordPress adds isolation and root-level control. Talk to our team about the right fit for your workload.

Summarize and Research with AI
Share on Social Media

Leave a Reply

Your email address will not be published. Required fields are marked *