The main route of compromise.
THE FACTS
Outdated plugins are the most common way WordPress sites are compromised.
Not WordPress itself, which updates reliably.
WHY
A vulnerability is found and published. Attackers scan for sites running the vulnerable version.
Automated, at scale, within hours.
WHAT PROTECTS YOU
Keeping plugins updated Removing plugins you do not use Using maintained plugins from reputable sources Never using nulled plugins
THE NULLED PLUGIN PROBLEM
Pirated versions frequently contain injected code.
That code is the point of distributing them.
THE DEACTIVATED PLUGIN PROBLEM
Files on the server can be exploited even when deactivated.
Delete rather than deactivate.
THE ABANDONED PLUGIN PROBLEM
A plugin no longer maintained will eventually have an unpatched vulnerability.
Replace it before that happens.
WHAT TO CHECK
Every plugin's last update date, twice a year.