WordPress security starts with keeping WordPress, themes and plugins up to date. Updates repair defects, close security gaps and keep software supported. The timing problem is simple: a vulnerability can be known or actively targeted before its developer has released a fix. You cannot install an update that does not exist yet.
That shortfall does not make updates less important. It means updates are one layer of a modern security plan, alongside vulnerability intelligence, protection while a fix is pending, careful deployment and a practical way to recover.
Patchstack’s State of WordPress Security in 2026 report looked at vulnerabilities and attack activity from 2025. Its findings help explain why the gap between disclosure and an installed fix deserves attention.
All figures above are Patchstack’s 2025 research, published in its 2026 report. The five-hour result is a weighted median for heavily exploited vulnerabilities, not a prediction for every new issue.
Updating WordPress is still essential
Updates remain the direct way to repair vulnerable software. When a plugin developer publishes a safe fix, installing it removes the underlying code flaw. The same principle applies to WordPress core and themes. WordPress’s own plugin guidance recommends keeping plugins current and having a recent backup before an update, because problems can occasionally occur.
Keep a clear inventory of what is installed, update software from its proper source, and remove components you no longer need. Pay attention to security notices for plugins and themes you rely on. If an update is available for an actively exploited issue, treat it as urgent and plan a prompt, sensible deployment rather than waiting for a routine weekly check.
These habits reduce avoidable exposure. They cannot close the period before a fix exists, and they do not remove the need to check that a change has worked after it is installed.
The vulnerability window: when a fix is not ready yet
A vulnerability is a weakness in software. A disclosure is information about that weakness becoming available to developers, site owners or the public. Attackers may begin testing for it before a corrected version has reached every site. The exact order and timing varies, but the gap can look like this:
Vulnerable code is in use
A plugin or theme contains a flaw in a feature or permission check.
The issue is identified
A researcher, vendor or security team validates the problem and coordinates a response.
Exposure window
The issue may be disclosed or targeted while a safe vendor update is still being prepared.
A fix is released
The developer publishes a corrected version, sometimes after testing or staged work.
The site is updated
The owner or manager installs the fix and checks that the site still works.
The practical gap is between a vulnerability becoming exploitable and the fixed software being safely installed. Virtual patching can help reduce exposure during that interval when a supported mitigation exists. It does not repair the plugin code or remove the need to update.
What virtual patching does
A normal software patch changes the vulnerable code itself. A virtual patch works around it: a targeted security rule recognises requests that match a known exploit path and blocks them before they can use the vulnerable behaviour. The plugin stays at its current version, so the original flaw remains until the developer’s real fix is installed.
Software update
Changes the plugin or theme code to correct the defect. This is the permanent fix and should be applied when available and appropriate.
Virtual patch
Adds a targeted request rule around a supported vulnerability. It can provide another layer while the developer’s update is pending or being scheduled; it does not change the underlying code.
Patchstack calls these rules vPatches. Its documentation describes them as specific firewall rules for known dangerous vulnerabilities in a site’s installed components, applied without changing code. Patchstack says its RapidMitigate system combines software composition analysis, threat intelligence and contextual prioritisation to apply site-specific rules where a relevant vulnerability is present. Read more about Patchstack protection at Big Wet Fish, and see the Patchstack vPatching documentation for the technical overview.
Coverage depends on the vulnerability, the affected component and whether a supported mitigation is available. Virtual patching is not a guarantee that every attack will be stopped, and it is not a substitute for an update, a backup or malware clean-up.
When attackers work in hours, weekly updates are one layer
Patchstack’s report says roughly half of the high-impact vulnerabilities it studied were observed being exploited within 24 hours. For the vulnerabilities attracting the greatest exploitation activity, the weighted median time to first observed exploit was about five hours. The selected group represented around 95% of observed exploitation activity for vulnerabilities published in 2025.
That statistic is weighted by observed activity and focuses on the most heavily targeted vulnerabilities. It does not mean that every vulnerability is attacked in five hours, or that every new disclosure is immediately exploitable. It does show why a routine update schedule alone may leave a temporary gap for a high-impact issue.
An illustrative sequence: a flaw is validated on Monday, disclosed on Tuesday, and scanning begins later that day. The plugin developer may still be preparing a tested release. A site owner who checks daily can be diligent and still have a period with no official update to install. Where a supported vPatch is available, it can add a targeted layer while the site owner arranges the real update.
Why a normal firewall may not see every WordPress flaw
Network and server firewalls remain important. They can help block broad classes of malicious traffic, protect services and reduce noise. But some WordPress vulnerabilities are specific to a plugin’s logic or a user’s permissions. An exploit request can resemble normal application traffic, so a generic rule may not have enough context to recognise that it is abusing a particular plugin flaw.
In January 2026, Patchstack published a controlled study covering 18 hosting providers. It tested 30 selected WordPress vulnerabilities on comparable installations using straightforward, pre-built proof-of-concept requests. Patchstack reported that the hosting environments blocked an average of 25.89% of the attempts; roughly 74% were not stopped by the tested hosting layers.
This was Patchstack’s test, not an independent BWF assessment. The result describes that study’s providers, security settings and test cases; it is not a universal score for every host or every attack. Patchstack noted that the WordPress-specific issues were harder for generic defences to block, while other attack types can be addressed effectively at the network or server layer. The lesson is to combine layers that solve different problems, not to discard a firewall. Read Patchstack’s methodology and results.
Plugins are the largest reported vulnerability surface
Patchstack attributed 91% of the new vulnerabilities it recorded in 2025 to plugins, 9% to themes and six low-priority issues to WordPress core. This is a count of reported vulnerabilities, not a count of successful compromises. It also does not mean that plugins are inherently unsafe or that WordPress core cannot have defects.
Plugins are how organisations add contact forms, payments, page builders, bookings, memberships, search optimisation, analytics and integrations. Every component adds code and functionality that must be maintained. A flaw in a popular, well-supported plugin does not by itself prove the product is badly made: widely used software can attract more security research because its impact may be larger.
Practical steps help keep that surface manageable:
- Choose software with a credible maintainer, clear update history and a support route.
- Remove inactive plugins, themes and accounts that are no longer needed.
- Keep a record of premium components too; they may not update through the public WordPress directory.
- Follow vulnerability notices for the products your site actually uses, then prioritise the affected versions.
- Use least-privilege accounts and reliable backups so one problem is less likely to become a larger incident.
Patchstack’s vulnerability database is one place to look up disclosed issues. A database entry is a prompt to check whether a component and version affect your site; it is not, by itself, proof that your site has been compromised.
Why “update everything immediately” needs a process
Installing a security fix promptly matters, especially when a vulnerability is actively exploited. At the same time, a production update can occasionally conflict with another plugin, custom code, a PHP version or a theme. A checkout, form or layout may behave differently after the change. That is why responsible maintenance includes a check after the update and a route back if something fails.
A useful operating pattern is protect → test/update → verify → recover if necessary. Risk should determine urgency. A high-impact, actively exploited vulnerability calls for faster action than a minor feature release, while a critical business site may need a short maintenance window, staging check or immediate rollback plan.
WP Umbrella gives the BWF team scheduled plugin updates, Safe Update and rollback options, monitoring and an additional WordPress backup layer. The exact checks depend on the Safe Update mode used. BWF’s current service describes weekly plugin updates and up to 50 days of additional WordPress backups alongside the hosting backups. See how WP Umbrella supports updates, monitoring and recovery.
WordPress security works best in layers
No single security product covers every risk. A practical stack gives each control a clear job and connects it to people who can review alerts, update software and respond if a site needs recovery.
Hosting infrastructure
Server configuration and hosting controls protect the environment around the website.
WordPress updates
Maintained core, themes and plugins receive the fixes their developers publish.
Vulnerability intelligence
Patchstack identifies relevant known issues and can apply targeted virtual patches where supported.
Malware and runtime protection
Monarx adds file and behavioural detection, runtime protection and remediation capabilities.
Monitoring
Uptime, performance and PHP-error signals help the team see when a site needs attention.
Backups and recovery
Additional WordPress backups and hosting backups provide practical recovery options.
People and oversight
The BWF team configures and manages the service and remains the point of contact.
Patchstack’s focus is WordPress component vulnerability intelligence and supported vPatches. Monarx adds malware detection, runtime and hosting-environment protection; its BWF page also describes active protection and remediation. WP Umbrella supports updates, monitoring and WordPress-level backups. These tools overlap in some protective functions, but they are used for different kinds of visibility and response. BWF’s Monarx overview explains its role in the wider hosting environment.
Layers reduce risk and can improve response and recovery; they cannot guarantee that a site will never be compromised. Good security is a maintained process, not a one-time installation.
How Big Wet Fish manages WordPress
BWF’s WordPress Management service brings these pieces together: scheduled plugin updates through WP Umbrella, Patchstack virtual patching for supported vulnerabilities, Monarx security, monitoring, additional backups with up to 50 days of retention, LiteSpeed-powered hosting and a team overseeing the service. It is added to an existing BWF hosting service; hosting is charged separately. The live WordPress Management page has current inclusions and pricing.
For more on the service model, see how BWF brings management, security, updates and backups together.
Does Patchstack mean I can stop updating WordPress?
No. A virtual patch can reduce exposure to a supported vulnerability while a software fix is pending, but the code still needs to be updated. Install the vendor’s corrected version when it is available and appropriate, verify the important parts of the site, and keep your recovery options current.
Want us to look after it for you?
BWF WordPress Management connects updates, vulnerability protection, malware and runtime defence, monitoring and recovery under one managed service. You keep one relationship with the team that configures and oversees it.
Sources & further reading
- Patchstack: State of WordPress Security in 2026 — vulnerability and exploitation findings for 2025.
- Patchstack: The Myth of Secure Hosting — January 2026 hosting-provider study and methodology.
- Patchstack: RapidMitigate — how site awareness, threat intelligence and mitigation rules fit together.
- Patchstack documentation: vPatching module — product description of virtual patches.
- Patchstack Vulnerability Database — current vulnerability records.
- WordPress.org: Manage Plugins — official update and backup guidance.


