Security

Why WordPress Sites Get Hacked: The Real Causes and How to Prevent Them

The real reasons business WordPress sites get hacked: outdated and abandoned plugins, nulled software, weak passwords, shared hosting accounts, infected computers and missing protection, with fixes for each.

Why WordPress Sites Get Hacked: The Real Causes and How to Prevent Them
On this page
  1. 1. Outdated plugins and themes
  2. 2. Abandoned plugins
  3. 3. Nulled (pirated) themes and plugins
  4. 4. Weak, reused or shared passwords
  5. 5. Several sites in one hosting account
  6. 6. An infected computer
  7. 7. Too many administrators
  8. 8. Old PHP and server software
  9. 9. No firewall, monitoring or backups
  10. It's rarely personal
  11. Already hacked?
Key takeaways
  • Most WordPress hacks come through outdated or abandoned plugins and themes, not core.
  • Nulled software, weak passwords, infected computers and too many admins are common causes.
  • One neglected site in a shared hosting account can infect all the others.

WordPress core itself is well maintained and patched quickly. Most hacked WordPress sites I clean were compromised through something around it: a plugin, a password, the hosting account or the way the site was managed. Knowing the real causes tells you exactly what to protect.

1. Outdated plugins and themes

Security researchers consistently find that most WordPress vulnerabilities are in plugins and themes, not core. Once a vulnerability is published, bots scan the internet for sites still running the old version, often within days.

Fix: update regularly and safely; see updating WordPress safely.

2. Abandoned plugins

Plugins that haven't been updated in years won't get security fixes, even when problems are found.

Fix: replace abandoned plugins with maintained alternatives and delete what you don't use.

3. Nulled (pirated) themes and plugins

"Free" copies of premium software often contain hidden malware and never receive updates.

Fix: use genuine licences; see the risks of nulled themes and plugins.

4. Weak, reused or shared passwords

Bots try common passwords and credentials leaked from other websites. Shared logins make it impossible to know who did what.

Fix: unique passwords, 2FA and individual accounts; see securing your login.

5. Several sites in one hosting account

If multiple websites share one hosting account, one neglected site, like an old test site or a forgotten microsite, can infect all the others. This is one of the most common causes of repeat infections I see.

Fix: delete old sites, keep every site updated, or isolate important sites in separate accounts.

6. An infected computer

Malware on the computer of someone who manages the site can steal saved FTP, hosting or WordPress passwords.

Fix: keep computers updated with antivirus, use SFTP instead of FTP and store passwords in a password manager.

7. Too many administrators

Every admin account is a potential entry point, especially old accounts for past staff or developers.

Fix: give people only the role they need and remove old accounts; see user roles explained.

8. Old PHP and server software

Unsupported PHP versions no longer receive security patches; see updating PHP.

9. No firewall, monitoring or backups

Without protection, attacks aren't blocked. Without monitoring, hacks go unnoticed for weeks. Without backups, recovery is slower and harder.

Fix: a firewall, uptime and file-change monitoring, and off-site backups; see the security checklist.

Choosing protection? See WordPress firewalls explained.

It's rarely personal

Most attacks are automated. Bots don't care whether you're a big brand or a small clinic; they look for any site with a known weakness, then use it for spam, redirects or phishing.

Already hacked?

See the clean-up process step by step, or get professional malware removal.

Need help with your website?

I'm Sameer, a freelance WordPress developer building fast, SEO-friendly websites since 2020. Tell me what you need and I'll reply with a plan and a fixed quote within 24 hours.

Found this useful? Share it:
Contact

Let's build your next website

Available for freelance projects, agency white-label work and long-term maintenance. Feel free to pass this along to your team or company.

Your details are emailed to me, then WhatsApp opens so we can chat right away.

Chat now