Website Hacking Statistics: How Often Do Websites Get Attacked?
Compiled from Patchstack’s 2026 State of WordPress Security report, Verizon’s 2025 Data Breach Investigations Report, and IBM’s 2025 Cost of a Data Breach report — how often websites are attacked, what’s actually being exploited, and who attackers are targeting.
📋 What’s in this page
Key Attack Statistics at a Glance
Attack-frequency figures vary depending on what’s being measured — automated bot scans, confirmed breaches, or disclosed vulnerabilities. Below are the most current, source-backed figures for each.
The WordPress Vulnerability Landscape
WordPress powers a large share of the web, which makes its plugin ecosystem — not WordPress itself — the dominant attack surface. Patchstack’s 2026 report, based on its own vulnerability database and disclosure program, breaks down where 2025’s 11,241 disclosed vulnerabilities actually came from.
| Source | Vulnerabilities (2025) | Share of Total |
|---|---|---|
| Plugins | 10,230 | 91% |
| Themes | 1,009 | 9% |
| WordPress core | 20 | <1% |
Source: Patchstack, State of WordPress Security 2026 (11,241 total vulnerabilities disclosed in 2025; the three rows above sum to 11,259 as independently rounded/categorized in Patchstack’s own published breakdown).
What kind of vulnerability is most common
Cross-site scripting (XSS) remains by far the most frequently disclosed vulnerability class in the WordPress ecosystem, followed by broken access control and CSRF — all three are common in poorly-vetted third-party plugins rather than in core WordPress code.
Patchstack’s 2026 report estimates that generic, signature-based web application firewalls block only around 12% of WordPress-specific attacks — because most WordPress exploits target logic flaws unique to a specific plugin version, not the kind of generic attack pattern a traditional WAF is built to catch. Keeping plugins updated and removing unused ones does more for most sites than a firewall alone.
How Fast Vulnerabilities Get Exploited
The window between a vulnerability becoming public and attackers actively exploiting it has been shrinking for years. Patchstack’s 2026 data shows just how little time site owners now have to patch after a disclosure.
Share of vulnerabilities exploited, by time since disclosure
Cumulative percentage of disclosed WordPress vulnerabilities that saw at least one real-world exploitation attempt within each time window.
Source: Patchstack, State of WordPress Security 2026.Free to reuse with attribution and a link to paidhosting.com
In practical terms: seven out of every ten exploitable WordPress vulnerabilities are being actively attacked somewhere within a week of becoming public knowledge, and 43% of disclosed vulnerabilities have no vendor patch available at the moment they’re disclosed. That combination — fast exploitation, slow patching — is why unmaintained plugins are consistently the most common entry point into a compromised WordPress site.
Small Businesses Are the Primary Target
Attackers overwhelmingly favor smaller, less-defended targets over high-profile enterprises — not because the payout per victim is larger, but because the cost of finding and compromising a victim is so much lower.
Small business breaches
- 43% of all cyberattacks specifically target small businesses
- 88% of small-business breaches involved ransomware or extortion malware
- Median ransom payment: $115,000, down from $150,000 the year before
Large organization breaches
- Only 39% of large-organization breaches involved ransomware or extortion malware
- Larger organizations more often face targeted, multi-stage intrusions rather than opportunistic attacks
- 64% of ransomware victims overall now refuse to pay, up from 50% two years earlier
Source: Verizon, 2025 Data Breach Investigations Report (reporting period: November 2023–October 2024).
How Long It Takes to Notice a Breach
For most breached organizations, the compromise itself is only half the problem — the other half is how long it goes unnoticed.
What This Means for Your Website
None of this data suggests hosting a website is uniquely dangerous — it suggests that most successful attacks are opportunistic, automated, and aimed at whatever is easiest to compromise, not specifically at you. A five-hour median window from disclosure to exploitation means the sites that get hit are disproportionately the ones running outdated plugins, not the ones targeted by name.
The practical takeaway tracks closely with the vulnerability data above: plugin hygiene matters more than almost anything else. Removing unused plugins, keeping active ones updated, and not treating a generic firewall as a substitute for patching addresses the overwhelming majority of the attack surface described in this data.
Sources & Methodology
Vulnerability and exploitation-speed figures come from Patchstack’s own vulnerability database and disclosure program, published in its 2026 State of WordPress Security report. Breach and small-business figures come from Verizon’s 2025 Data Breach Investigations Report, based on its analysis of confirmed data breaches submitted by contributing organizations worldwide. Breach-cost and detection-time figures come from IBM’s 2025 Cost of a Data Breach report. This page is reviewed and updated as newer annual reports are published.
- Patchstack — State of WordPress Security 2026 / WordPress Vulnerability Database, 2025 statistics
- Verizon — 2025 Data Breach Investigations Report (DBIR)
- IBM Security — Cost of a Data Breach Report 2025
- University of Maryland, A. James Clark School of Engineering — cyberattack frequency research (widely-cited baseline)
Cite this analysis
https://www.paidhosting.com/website-hacking-statistics/
Findings on this page may be reproduced with attribution and a link back to this page. Press and data enquiries: [email protected]