WordPress Security for Small Businesses: What You Need to Know

WordPress can be kept secure, but it takes ongoing attention that most small businesses underestimate: keep the core, the theme and every plugin updated, use strong logins, and run backups you have actually tested. WordPress is not inherently unsafe, but it is the most popular website software in the world, which makes it the biggest target, and every plugin you add is another possible way in. For a small business, that security burden is often the hidden downside of running it.

Here is what actually matters, and how to decide whether the job is worth carrying.

Update, September 2026: what CVE-2026-87902 means for your site

On 22 September 2026, WordPress released version 7.1.2 to fix CVE-2026-87902, a critical vulnerability in WordPress core itself, rated 9.2 (critical) on the standard CVSS scale. It affects every WordPress version from 4.7.0 to 7.1.1, and fixes were released for older branches too (7.0.6, 6.9.9, 6.8.10 and back to 4.7.37). According to Patchstack, attackers started probing sites for it at 11:49 UTC on the same day the fix came out.

In plain English, it is a flaw in how WordPress decides which page template to load. In some setups it lets an attacker make the site load a file it should never touch, and in the worst case run their own code. Not every site is exploitable: it depends on the theme having a particular folder structure and on how the server’s PHP is configured. You cannot easily tell that from the outside, so the sensible move is the same for everyone.

What to do now. Check your site is on 7.1.2, or the patched release for your older branch, under Dashboard, then Updates. If automatic background updates are switched on it may already have updated itself, but check rather than assume. If someone else manages your site, ask them to confirm in writing that it has been patched.

The bigger lesson is that this one was in core, not a plugin. Even a well-kept WordPress site depends on someone applying fixes within hours of them being published, because attackers now move that fast. That routine is what the rest of this post is about.

Why is WordPress such a target?

WordPress runs a large share of all websites. Attackers go where the numbers are. Most attacks are not aimed at you personally. They are automated sweeps looking for a known weakness: an old plugin, a default login, a theme that stopped getting patches two years ago. Being a small firm in Hassocks or Burgess Hill is no protection, because the scan does not care who you are. It cares whether you are an easy way in.

That is the trade-off of popularity. The same ubiquity that means help is everywhere also means the threats are everywhere. You do not need to be interesting. You need to be unpatched.

Where does the risk actually come from?

WordPress core itself is reasonably well looked after by its developers, although, as the September 2026 fix shows, even core is not immune. Most of the risk sits around it.

Plugins and themes. This is the big one. Every plugin is third-party code written by someone you have never met. An out-of-date or abandoned plugin is the most common way WordPress sites get compromised. Patchstack counted 11,334 new vulnerabilities in the WordPress ecosystem in 2025, 91% of them in plugins, and 46% were made public before a fix was available. The more you run, the larger the target. A contact form, an SEO add-on, a slider, a backup tool and a security plugin can all be useful. They are also five extra codebases that need watching.

Skipped updates. Updates often patch security holes that have already been published. Leave them for a month and you are running software with a known, documented weakness. Automated scanners find those quickly.

Weak logins. A simple admin password, reused from somewhere else, with no two-factor login, is an open door to guessing attacks. admin as a username still appears more often than it should.

Cheap or poorly configured hosting. The server itself can be the weak point: outdated PHP, shared accounts, no isolation from the next site on the box.

Notice the pattern. Most of these are things you bolt onto WordPress and then have to maintain. It is the same pattern behind its running costs. Security is not a setting you flick once. It is a routine.

How do you keep a WordPress site reasonably safe?

If you run WordPress and intend to keep it, these are the essentials.

Update everything, promptly: core, theme and all plugins. This is the single most important habit. Do it on a copy first if you can, because an update can break a layout. Then do it on the live site anyway.

Use as few plugins as you can. Only keep what you genuinely use. A plugin you installed for a Christmas banner in 2023 and never deleted is still a door.

Strong logins and two-factor authentication on the admin account. Unique password, not the one from the email inbox.

A security plugin, if you stay on WordPress, to add a firewall and some monitoring. Yes, that is another plugin to configure and keep updated.

Reliable, tested backups, so that if the worst happens you can restore rather than rebuild. A backup you have never restored from is a story.

Done consistently, this keeps a WordPress site reasonably safe. The catch is the word consistently. It only works if someone actually keeps it up, including the months you are busy.

What does a hack actually cost a small business?

It is worth being clear about the stakes without scaremongering. A compromised site can be defaced, used to send spam, quietly injected with links that harm your Google ranking, or taken offline entirely. Cleaning it up costs time and often a developer invoice. If customer data is involved there are wider obligations too, including the need to work out what was taken and who to tell.

For a small business, a hacked website at the wrong moment is a genuine disruption. You lose the shopfront. You lose trust if a customer sees a spam page under your name. You spend a week on recovery instead of jobs. “We will deal with it if it happens” is a poor plan. Recovery is slower and more expensive than the boring monthly updates you skipped. I will not invent a typical cleanup bill. The figure depends on the mess. The cost of a lapse is almost always higher than the cost of the routine.

Is there a lower-maintenance alternative?

The honest question for a small business is not “can WordPress be secured”. It can. The question is “do I want the ongoing job of securing it”. If the answer is no, a managed, purpose-built site changes the picture: a far smaller attack surface, no plugin sprawl, updates and backups handled for you, so it is not a routine you have to remember.

That is part of the thinking behind our WordPress alternative. If you already run WordPress and are tired of the upkeep, we move you off it and keep your Google ranking. See move from WordPress. After the move, care of the new site is ordinary hosting and updates, not a WordPress security retainer. What that includes is on website maintenance in Sussex.

To be clear about what we offer: we build and manage the replacement site, including keeping it secure and backed up. We are not a managed IT security provider. We do not run a monitoring helpdesk for your wider systems. We do not keep WordPress alive on a care plan. If you want WordPress support, that is a different kind of firm.

A one-page replacement is £99 to set up and £29 a month, or £299 a year, and typically live in about five working days once we have what we need. Larger rebuilds are quoted.

Frequently asked questions

Was my WordPress site affected by CVE-2026-87902?

Any WordPress site running version 4.7.0 to 7.1.1 had the vulnerable code, but only some setups could actually be exploited, depending on the theme and the server’s PHP configuration. Updating to 7.1.2, or the patched release for your branch, closes it. If you are not sure which version you are on, log in and check Dashboard, then Updates, or ask whoever manages the site.

Is WordPress safe for a small business?

It can be, with consistent upkeep: prompt updates, few plugins, strong logins with two-factor authentication, a security tool and tested backups. The risk is that this is an ongoing routine, and a lapse is often how sites get compromised. Safe is achievable. It takes attention you may not want to give it.

Why do WordPress sites get hacked so often?

Mostly through out-of-date or poorly maintained plugins and themes, skipped updates, and weak logins, not flaws in WordPress core. Because WordPress is so widely used, automated attacks target it constantly, so any small weakness tends to be found.

Do I have to keep updating WordPress forever?

Yes, if you run it. WordPress core, your theme and every plugin need ongoing updates, largely for security. Stopping leaves known holes open. Avoiding that permanent routine is one reason small businesses move to a managed site where updates are handled for them.

Does Page Forge look after WordPress sites?

No. We replace WordPress. We do not retain it, patch plugins, or sell a WordPress care plan. If you want us to take the site on, the work is a move to a hand-built site, not a monthly visit to wp-admin.

What is the biggest WordPress security mistake?

Leaving updates for later, especially on plugins you barely remember installing. The second is a weak admin login with no two-factor authentication. Either one is enough for an automated scan to succeed.

Can a hacked WordPress site recover its Google ranking?

Often, if you clean it properly, restore clean content, and fix the injected pages before Google has treated the site as junk for long. Prevention is cheaper. A move off WordPress does not by itself restore a ranking you already lost to spam. You still have to clean the mess first.

arrow_back All articles

Ready to get your business online?

Drop us a message or give us a call. No pressure, no jargon, just a quick chat about what you need.

alternate_email
call
location_on
Based inHassocks, West Sussex, serving Mid Sussex & the UK

Send us a message

Or message us on WhatsApp
chat