Back to News & Blog
Agency AI Development Enterprise

Website security and why you need to act now

Summary of "Website Security and Why You Need to Act Now"

The document highlights the escalating threat landscape for websites and the urgent need for enhanced security measures. Key points include:

1. Increased Automated Attacks:
- AI-driven bot networks are exploiting disclosed vulnerabilities at an unprecedented scale, targeting thousands of sites simultaneously.
- Even smaller or lesser-known sites are at risk due to the indiscriminate nature of these attacks.

2. Common Entry Points:
- Unpatched Plugins: Outdated or unmaintained plugins in platforms like WordPress are primary targets for hackers.
- Weak Authentication: Sites with weak passwords and without multi-factor authentication (2FA) are particularly vulnerable.

3.

As an agency, we host and manage hundreds of websites for our clients. Over the past few months alone, we have seen more attempted attacks across these websites than ever before.

We can’t stress this enough, website and platform security has to be a priority, not an afterthought.

Automated attacks from AI Bot networks

With the huge uptick in AI, Bot networks are now surfacing disclosed vulnerabilities, crawling the web for every site running that affected component, and exploiting them in one automated pass, thousands at a time.

AI has made building and running those systems faster and cheaper.

“It's much less a manual decision now as to which sites to attack. They are doing it to thousands at a time. Even if a site is smaller, receives less traffic, or isn't widely known in the public domain, it's pretty indiscriminate as to which sites will be targeted.”
Sam Phillips Managing Director

SoBold works across multiple CMS platforms for our clients, but WordPress is where the largest share of our hosting and management work sits.

Much of what follows is drawn from our WordPress client base, though the same shift applies across every platform we work across.

Wordfence, one of the leading security plugins in the WordPress ecosystem, is a plugin used to block malicious login attempts, known exploit attempts, and bot traffic before any of it reaches the site itself.

n the space of 24 hours, it went from blocking around 200 million attacks per day to 600 million.

Patchstack’s State of WordPress Security in 2026 report puts the weighted median time from disclosure to first exploit at five hours for the most heavily targeted WordPress vulnerabilities, with roughly half of high-impact vulnerabilities attacked within 24 hours.

Once your site is affected, it has become a race against time, and site owners need to act quickly.

How sites are actually being compromised

Typically, two entry routes account for most of the compromises we deal with.

Unpatched plugins

WordPress is open source, and typically WordPress sites have multiple plugins installed.

A plugin is a piece of third-party software added to a site to extend what it can do, whether that’s a contact form, an SEO tool, an events calendar, a payment gateway, or any of the thousands of other functions site owners rely on. Each one is built and maintained by a separate developer or company, and each one runs code on your site.

Plugins need regular maintenance, if they’re not kept updated, they can become the entry point into every site they’re installed on.

Sites often carry plugins they no longer need, and similarly use plugins that are not actively maintained or from reputable sources. These become an even easier way in for hackers.

Multi-factor authentication

The second is ensuring you have gated access to the back end of the site through user accounts as user accounts with weak passwords and without two-factor authentication are easily accessible by AI bots.

Two-factor authentication requires an authenticator app to get into the site, so it locks down access.

What the attacks look like

In some cases, attackers install malicious plugins to the back end of the site, aiming to access and store the data held there.

In most cases, though, code is injected onto the front end of the site. Depending on what has been injected, it can redirect visitors to a site under the attacker’s control, display fake login or payment forms that capture what the visitor types, or send data entered on the site to a third-party server.

Hosting protection

At SoBold, we take further precautions with our hosting offering to reduce the chances of an attack.

Our dedicated hosting sits on a fully-managed private cloud and we have configured firewalls, IP access lists, and anti-phishing and attack detection technologies that filter a large share of malicious traffic at the network layer.

Multi-level backups are taken locally and remotely and tested for restorability, which gives us a clean point to work back to rather than cleaning an infected database in place.

It’s worth pointing out that sites on shared or lower-cost hosting plans often don’t have most of this.

The same security picture across other platforms

These security issues are not just impacting sites using WordPress. Earlier this week, on 25 August 2026, Next.js published a security release (versions 16.3.3 and 15.5.24) fixing two critical vulnerabilities, both allowing unauthenticated remote code execution: one through AVIF image optimisation and one affecting Windows-hosted servers. 

Umbraco released security patches on 18 August 2026 across Umbraco CMS, Umbraco Forms, and Umbraco AI, addressing four vulnerabilities, one of which was classified as high severity, and Sitecore has faced a run of critical issues across its Experience Manager, Experience Platform, and Experience Commerce products.

Ensuring that your platform is being actively maintained is now more important than ever.

Why regular patching has become time-critical

Monthly updates are the baseline we recommend to every client, alongside a faster response route for any high or critical vulnerabilities disclosed in between cycles.

“The average time now for mass exploitation on those heavily targeted vulnerabilities is just five hours. Even the slightly less exploited ones are often starting to be exploited within 24 hours of Wordfence announcing them.”
Sam Phillips Managing Director

Alongside our monthly updates, we’re now proactively monitoring installed plugins and any announced vulnerabilities from a central dashboard. This means where any critical or high severity vulnerabilities are found, we’re able to jump in straight away and apply the necessary updates (rather than waiting for the standard monthly update cycle).

How we approach patching for our WordPress clients

To make sure our clients’ websites are patched, we make sure we complete any updates on a staging site.

We take a fresh copy of the live site and go through WordPress core and plugin updates. On completion, our clients receive a report listing the successful updates, detailing what was updated and from which version to which. Keeping this audit trail ensures we can keep track of the version history.

Given the frequency of ‘high’ and ‘critical’ vulnerabilities we are now seeing, we also apply ad hoc patching between update cycles.

What remediation looks like when a site is compromised

Despite all of that, we are still seeing the sites we manage get targeted and in the last 2 months alone, we have had 5 of our clients’ sites hacked.

When a site is compromised, our team works to immediately seek out any malicious plugins and unknown admin accounts.

Where there has been any period of time between the compromise happening and us catching it, there are often other affected files and, in some cases, the database itself also needs to be cleaned.

Once this has been identified, we run a full Wordfence scan and review every flagged file, then remove it or revert to a known-good version. We then need to reinstall WordPress core from a fresh download and update every plugin on the site again.

Where there’s any sign the admin area was accessed, every user is told to reset their password and we make sure 2FA is added to every account.

The case for regular patching

If your site has never been hacked, it’s easy to assume it doesn’t need regular patching. However, the sharp rise in automated attacks over the last twelve months means that every site is now under serious threat.

Monthly patching should, in most cases, be enough to flag high or critical vulnerabilities, but anything less frequent means there is a considerably higher chance of hacking.

The costs of the remediation, the lost trading or lead-generation time while the site is down or untrusted is business critical. For finance and legal clients in particular, an incident can trigger a set of reporting obligations; including notifications to the relevant authority bodies, and the requirement for a full incident debrief afterwards.

The whole process is time-consuming and expensive to work through, on top of the technical clean-up.

What you can do to make sure your site is as secure as it can be

First and foremost, speak to your agency managing your site, and at the very least make sure you add two-factor authentication on every account and audit all users.

Commit to more regular plugin updates to be able to cover high and critical vulnerabilities that may arise, and make sure any plugins that you have on your site come from a reputable, actively maintained source.

Check where your site is hosted and what that hosting includes. Shared hosting plans and lower-cost providers rarely include the firewall configuration, intrusion detection, continuous server patching, and tested backups that a dedicated setup does.

What we expect to see over the next 12 months

We expect these trends to continue and become more prevalent as the use of AI ramps up further.

Every agency is going to need to focus much more on security and adopt a security-first mindset.

In the medium term, we expect to see the industry look at other ways of protecting sites more fundamentally. That includes locking the CMS itself away from the public internet, and AI-led ways of managing content that remove the need for a publicly facing admin altogether. Both are things we are actively looking into as an agency.

Let’s scope your next project.

Whether you’re in financial services, healthcare, energy or another sector, we start every project with a conversation about your requirements. No commitment, just a discussion about your needs.

Schedule a consultation