Answering "Is WordPress Dangerous?" - Thinking About Why It's Targeted and Why It Continues to Be Chosen Based on July's Vulnerabilities
2026.10.02
Upon learning of an emergency update for WordPress released this July, you might have wondered, "Is our company's site okay?" You might also be wondering if you should continue using it, having heard voices saying, "WordPress is dangerous."
To put it simply, using WordPress itself doesn't immediately mean danger. What's important is whether continuous maintenance, such as necessary updates and backups, is being performed for vulnerabilities found in the WordPress core, plugins, and themes.
Editing by Akira Kimura
"wp2shell" Showed the "Everyday" Risks of WordPress
What Happened?
On July 17, 2026 (early morning of the 18th Japan time), WordPress.org, the developer of WordPress, released an emergency update for the core program that forms the foundation of websites: "WordPress core."
Two vulnerabilities were fixed this time, with the official designation of one as "critical" (the highest severity) and the other as "high." Attacks combining these two are commonly known as "wp2shell."
In a cautionary notice dated July 22, the IPA (Information-technology Promotion Agency) stated that even with a standard WordPress site configuration, a third party without administrator privileges could potentially operate the site from outside.
Furthermore, on July 21 (local time), the US cybersecurity agency CISA added this vulnerability to its list of "vulnerabilities confirmed to be actively exploited."
WordPress.org has enabled "forced automatic updates" for affected sites, meaning updates will be applied without user intervention. However, IPA warns that automatic updates might not work or could fail depending on the site's environment and settings. They urge administrators to check their update status in the dashboard and perform manual updates if necessary.
In other words, the first thing site administrators should do is not assume "it must have been updated automatically," but to actually check if their current version is the patched one.
Why is it so often targeted, yet still so popular?
Why WordPress is a Frequent Target
According to a survey by a specialized organization as of September 28, 2026, WordPress is used by 40.2% of all websites and 58.7% of websites using CMS (Content Management Systems). Within Japan, WordPress's share among CMS-powered sites is as high as 82.8% (as of June 2026).
A large user base means that attackers can potentially target many sites with a single attack method. Therefore, the high number of users is seen as a reason why WordPress is an easy target.
Another characteristic is that WordPress is open-source. Open-source means that the source code, which is like the blueprint of the program, is publicly available for anyone to inspect. While this allows developers and security researchers worldwide to find and report vulnerabilities, attackers can also analyze the code. Furthermore, WordPress allows the use of plugins and themes developed by third parties, which can lead to variations in quality and update practices among different developers. The recent wp2shell vulnerability, for instance, was a security flaw reported by an external security researcher, for which WordPress released a fix.
This means it's impossible to completely eliminate the discovery of vulnerabilities in WordPress. The crucial point is how quickly a fix can be developed and applied to sites after a vulnerability is found.
Reasons Why It Remains Popular Despite This
There's a reason WordPress is widely used for corporate websites. For example, you can set the scope of operations for each user, such as administrators and editors. Also, because it's open source, there are no license fees, making it easier to reduce development time and costs. Furthermore, the large number of users means there's abundant information online about how to operate it and deal with problems, which contributes to ease of implementation and operation.
What's important here is that being "easy to target" and "not being able to operate safely" are not the same thing. In the wp2shell incident in July, WordPress itself fixed the vulnerability and even implemented forced automatic updates. The remaining challenge is to confirm whether the corrected version has been applied to each site and whether there's a system in place to continue necessary updates.
The condition for continued safe use is a "maintenance system"
It becomes dangerous when it's "left unattended"
As the IPA's warning indicates, assuming "it must be updating automatically" poses a risk in site management. Automatic updates are a convenient mechanism, but they may not function properly depending on the environment and settings.
Also, as KUSANAGI explained in their September report, WordPress primarily provides ongoing fixes for the latest version, and providing fixes for older versions is treated as a special measure. If you continue to use an older version, you may not receive fixes for new vulnerabilities in the future. Some companies that provide WordPress maintenance services indicate that sites where updates have been delayed for more than six months are at high risk of their vulnerabilities being exploited.
3 questions to check first
If you want to check the security of your website, please check the following three points first.
1. Is there a designated "maintenance contact" for this site?
It doesn't matter if it's an internal staff member or an external production/maintenance company. Being able to answer "Who is managing this?" by name is one benchmark.
2. Are the WordPress core, plugins, and themes regularly updated, and are backups performed regularly?
It's not enough to say, "I update the WordPress core, but I don't know about the plugins." It's important to confirm that the core, plugins, and themes are updated regularly and that backups are performed regularly to recover in case of an emergency.
3. Do you have a designated contact person and a rollback procedure in case of problems?
When issues arise, such as "the site is no longer displayed" or "an unauthorized page is shown," who should be contacted, who will confirm the situation, and how will it be restored? It's best to have a plan in place, ideally specifying "who," "what to monitor," "within how many hours of the problem occurring," and "what actions to take."
Whether WordPress is dangerous depends not on "whether it's used," but on "whether it's maintained."
It's not as simple as "WordPress is dangerous" or "WordPress is safe." What's important is whether you have a system in place to recover from problems, assuming vulnerabilities will be discovered.
First, try answering the following three questions.
- Is there a designated maintenance person?
- Are updates and backups for the core, plugins, and themes being performed?
- Are the contact person and recovery procedure decided in case of a problem?
If you hesitate on any item, that's the "next area to address" for your current site. WordPress risks can't be eliminated entirely. That's precisely why you need to create a system that doesn't ignore potential vulnerabilities, assuming they will be found. That's the basic principle for using WordPress safely and long-term.