Website Hacking Statistics: How Often Do Websites Get Attacked?

Website Security Research — PaidHosting.com

Website Hacking Statistics: How Often Do Websites Get Attacked?

Compiled from Patchstack’s 2026 State of WordPress Security report, Verizon’s 2025 Data Breach Investigations Report, and IBM’s 2025 Cost of a Data Breach report — how often websites are attacked, what’s actually being exploited, and who attackers are targeting.

🛡️ Patchstack · Verizon DBIR · IBM 📈 2025–2026 data 🔄 Updated September 2026

Key Attack Statistics at a Glance

Attack-frequency figures vary depending on what’s being measured — automated bot scans, confirmed breaches, or disclosed vulnerabilities. Below are the most current, source-backed figures for each.

91%of all disclosed WordPress vulnerabilities in 2025 were found in plugins, not WordPress corePatchstack · 2025
43%of disclosed vulnerabilities were still unpatched at the time they were publicly disclosedPatchstack · 2026
~5 hrsmedian time from public disclosure to the first mass-exploitation attemptPatchstack · 2026
43%of all cyberattacks specifically target small businessesVerizon · 2025 DBIR
88%of small-business breaches involved ransomware or extortion malware, vs. 39% at large organizationsVerizon · 2025 DBIR
194 daysaverage time to identify a breach, plus another 64 days to contain itIBM · 2025 Cost of a Data Breach

The WordPress Vulnerability Landscape

WordPress powers a large share of the web, which makes its plugin ecosystem — not WordPress itself — the dominant attack surface. Patchstack’s 2026 report, based on its own vulnerability database and disclosure program, breaks down where 2025’s 11,241 disclosed vulnerabilities actually came from.

SourceVulnerabilities (2025)Share of Total
Plugins10,23091%
Themes1,0099%
WordPress core20<1%

Source: Patchstack, State of WordPress Security 2026 (11,241 total vulnerabilities disclosed in 2025; the three rows above sum to 11,259 as independently rounded/categorized in Patchstack’s own published breakdown).

What kind of vulnerability is most common

Cross-site scripting (XSS) remains by far the most frequently disclosed vulnerability class in the WordPress ecosystem, followed by broken access control and CSRF — all three are common in poorly-vetted third-party plugins rather than in core WordPress code.

  • Cross-Site Scripting (XSS): 40.7% of all disclosed vulnerabilitiesSource: Patchstack Vulnerability Database, 2025
  • Broken Access Control: 15.2% of all disclosed vulnerabilitiesSource: Patchstack Vulnerability Database, 2025
  • Cross-Site Request Forgery (CSRF): 12.9% of all disclosed vulnerabilitiesSource: Patchstack Vulnerability Database, 2025
  • SQL Injection: 5.8% of all disclosed vulnerabilitiesSource: Patchstack Vulnerability Database, 2025
  • ⚠️
    Traditional firewalls miss most of these

    Patchstack’s 2026 report estimates that generic, signature-based web application firewalls block only around 12% of WordPress-specific attacks — because most WordPress exploits target logic flaws unique to a specific plugin version, not the kind of generic attack pattern a traditional WAF is built to catch. Keeping plugins updated and removing unused ones does more for most sites than a firewall alone.

    How Fast Vulnerabilities Get Exploited

    The window between a vulnerability becoming public and attackers actively exploiting it has been shrinking for years. Patchstack’s 2026 data shows just how little time site owners now have to patch after a disclosure.

    Share of vulnerabilities exploited, by time since disclosure

    Cumulative percentage of disclosed WordPress vulnerabilities that saw at least one real-world exploitation attempt within each time window.

    Within 6 hours20%
    Within 24 hours45%
    Within 72 hours58%
    Within 7 days70%

    Source: Patchstack, State of WordPress Security 2026.Free to reuse with attribution and a link to paidhosting.com

    In practical terms: seven out of every ten exploitable WordPress vulnerabilities are being actively attacked somewhere within a week of becoming public knowledge, and 43% of disclosed vulnerabilities have no vendor patch available at the moment they’re disclosed. That combination — fast exploitation, slow patching — is why unmaintained plugins are consistently the most common entry point into a compromised WordPress site.

    Small Businesses Are the Primary Target

    Attackers overwhelmingly favor smaller, less-defended targets over high-profile enterprises — not because the payout per victim is larger, but because the cost of finding and compromising a victim is so much lower.

    Small business breaches

    • 43% of all cyberattacks specifically target small businesses
    • 88% of small-business breaches involved ransomware or extortion malware
    • Median ransom payment: $115,000, down from $150,000 the year before

    Large organization breaches

    • Only 39% of large-organization breaches involved ransomware or extortion malware
    • Larger organizations more often face targeted, multi-stage intrusions rather than opportunistic attacks
    • 64% of ransomware victims overall now refuse to pay, up from 50% two years earlier

    Source: Verizon, 2025 Data Breach Investigations Report (reporting period: November 2023–October 2024).

    How Long It Takes to Notice a Breach

    For most breached organizations, the compromise itself is only half the problem — the other half is how long it goes unnoticed.

  • 194 days is the average time to identify a data breach after it begins.Source: IBM, Cost of a Data Breach Report 2025
  • An additional 64 days are needed on average to contain a breach once it’s identified — a total lifecycle of roughly 258 days from compromise to containment.Source: IBM, Cost of a Data Breach Report 2025
  • The global average cost of a data breach reached $4.88 million in 2025; in the United States specifically, the average climbs to $9.36 million.Source: IBM, Cost of a Data Breach Report 2025
  • Roughly 2,200 cyberattacks occur every day worldwide, a figure that has circulated widely since a University of Maryland study first measured attack frequency against test systems — still commonly cited as a baseline for daily attack volume.Source: University of Maryland, Clark School of Engineering (widely cited baseline figure)
  • What This Means for Your Website

    None of this data suggests hosting a website is uniquely dangerous — it suggests that most successful attacks are opportunistic, automated, and aimed at whatever is easiest to compromise, not specifically at you. A five-hour median window from disclosure to exploitation means the sites that get hit are disproportionately the ones running outdated plugins, not the ones targeted by name.

    The practical takeaway tracks closely with the vulnerability data above: plugin hygiene matters more than almost anything else. Removing unused plugins, keeping active ones updated, and not treating a generic firewall as a substitute for patching addresses the overwhelming majority of the attack surface described in this data.


    Sources & Methodology

    Vulnerability and exploitation-speed figures come from Patchstack’s own vulnerability database and disclosure program, published in its 2026 State of WordPress Security report. Breach and small-business figures come from Verizon’s 2025 Data Breach Investigations Report, based on its analysis of confirmed data breaches submitted by contributing organizations worldwide. Breach-cost and detection-time figures come from IBM’s 2025 Cost of a Data Breach report. This page is reviewed and updated as newer annual reports are published.

    • Patchstack — State of WordPress Security 2026 / WordPress Vulnerability Database, 2025 statistics
    • Verizon — 2025 Data Breach Investigations Report (DBIR)
    • IBM Security — Cost of a Data Breach Report 2025
    • University of Maryland, A. James Clark School of Engineering — cyberattack frequency research (widely-cited baseline)

    Cite this analysis

    Paid Hosting. Website Hacking Statistics: How Often Do Websites Get Attacked? September 2026. Compiled from Patchstack, Verizon DBIR, and IBM Cost of a Data Breach research.
    https://www.paidhosting.com/website-hacking-statistics/

    Findings on this page may be reproduced with attribution and a link back to this page. Press and data enquiries: [email protected]