5 Hours From Disclosure To Mass Exploitation.

A towering wall of identical pigeonhole slots, every one filled, lit red
Estimated Exposure: Every WordPress site running a plugin with a published vulnerability — and 11,334 new ones were found in the ecosystem during 2025 alone. What Happened: Patchstack publishes an annual measurement of the WordPress security landscape. The 2026 report, released in February, timed how long it takes a newly disclosed vulnerability to travel from public advisory to mass exploitation across the internet. The median is five hours. Not five days, not five weeks — five hours. The same report found that 46% of vulnerabilities had no patch available at the moment they were disclosed. The hole is announced to the world before the fix exists. And the volume is climbing: 11,334 new vulnerabilities in the WordPress ecosystem in 2025, a 42% increase on the year before. The Message: "I keep everything updated" stopped being a defence. You cannot install a patch that has not been written yet, and once it is written you have hours, not weekends. The same report found only 26% of vulnerability attacks were stopped at the hosting layer — the other three quarters walked straight past the host the business was already paying for. The question was never whether you update. It is whether anyone is watching in between. Source: Patchstack, State of WordPress Security in 2026, published 25 February 2026.

Patchstack measured the median time from public disclosure to mass exploitation of a WordPress vulnerability at five hours. 46% have no patch when disclosed.

Get Certified Before
You're the Next Headline

Every story on this page started the same way — a published vulnerability, a site nobody was watching, and weeks before anyone noticed. The free scan looks at your site from the outside, the same way an automated scanner does. It costs nothing, there is no obligation, and it takes about thirty seconds to start.

Scan My Site — Free