Answering "Is WordPress Dangerous?" - Thinking About Why It's Targeted and Why It Continues to Be Chosen Based on July's Vulnerabilities
2026.10.07
Upon learning of an emergency update for WordPress released this July, you might have wondered, "Is our company's site okay?" You might also be wondering if you should continue using it, having heard voices saying, "WordPress is dangerous."
To put it simply, using WordPress itself doesn't immediately mean danger. What's important is whether continuous maintenance, such as necessary updates and backups, is being performed for vulnerabilities found in the WordPress core, plugins, and themes.
Editing by Akira Kimura
"wp2shell" Showed the "Everyday" Risks of WordPress
What Happened?
On July 17, 2026 (early morning of the 18th Japan time), WordPress.org, the developer of WordPress, released an emergency update for the core program that forms the foundation of websites: "WordPress core."
Two vulnerabilities were fixed this time, with the official designation of one as "critical" (the highest severity) and the other as "high." Attacks combining these two are commonly known as "wp2shell."
In a cautionary notice dated July 22, the IPA (Information-technology Promotion Agency) stated that even with a standard WordPress site configuration, a third party without administrator privileges could potentially operate the site from outside.
Furthermore, on July 21 (local time), the US cybersecurity agency CISA added this vulnerability to its list of "vulnerabilities confirmed to be actively exploited."
WordPress.org has enabled "forced automatic updates" for affected sites, meaning updates will be applied without user intervention. However, IPA warns that automatic updates might not work or could fail depending on the site's environment and settings. They urge administrators to check their update status in the dashboard and perform manual updates if necessary.
In other words, the first thing site administrators should do is not assume "it must have been updated automatically," but to actually check if their current version is the patched one.
What Happened?
It's not just the core WordPress software that you need to be careful about. WordPress has 'plugins' that add functionality and 'themes' that determine the design and display of your site, and vulnerabilities can be found in these as well.
KUSANAGI, operated by GMO Prime Strategy (https://kusanagi.tokyo/), independently aggregates vulnerabilities in WordPress core, plugins, and themes that meet certain criteria based on information released by Wordfence, and publishes them weekly.
The criteria include plugins and themes with over 100,000 active installations on WordPress.org and support for Japanese translation. For the week of September 17-23, 2026, 58 vulnerabilities were reported and disclosed, of which 12 were related to the WordPress core. Additionally, 28 of the 58 vulnerabilities could be exploited by unauthenticated attackers.
However, it's important to note that this number of 58 does not directly evaluate the 'security of WordPress.' KUSANAGI itself states that the number of listings represents the number of reported and disclosed vulnerabilities and is not an indicator for comparing product security. It simply means that 58 vulnerabilities were reported and disclosed during that week within the scope extracted and aggregated under specific conditions.
The important thing is that not only the WordPress core but also plugins and themes are continuously being discovered for vulnerabilities, and updates are being made to address them.
[Source]
KUSANAGI "Summary of WordPress Theme and Plugin Vulnerability Information (2026/09/17-2026/09/23))」
Why is it so often targeted, yet still so popular?
Why WordPress is a Frequent Target
According to a survey by a specialized organization as of September 28, 2026, WordPress is used by 40.2% of all websites and 58.7% of websites using CMS (Content Management Systems). Within Japan, WordPress's share among CMS-powered sites is as high as 82.8% (as of June 2026).
A large user base means that attackers can potentially target many sites with a single attack method. Therefore, the high number of users is seen as a reason why WordPress is an easy target.
Another characteristic is that WordPress is open-source. Open-source means that the source code, which is like the blueprint of the program, is publicly available for anyone to inspect. While this allows developers and security researchers worldwide to find and report vulnerabilities, attackers can also analyze the code. Furthermore, WordPress allows the use of plugins and themes developed by third parties, which can lead to variations in quality and update practices among different developers. The recent wp2shell vulnerability, for instance, was a security flaw reported by an external security researcher, for which WordPress released a fix.
This means it's impossible to completely eliminate the discovery of vulnerabilities in WordPress. The crucial point is how quickly a fix can be developed and applied to sites after a vulnerability is found.
Reasons Why It Remains Popular Despite This
There's a reason WordPress is widely used for corporate websites. For example, you can set the scope of operations for each user, such as administrators and editors. Also, because it's open source, there are no license fees, making it easier to reduce development time and costs. Furthermore, the large number of users means there's abundant information online about how to operate it and deal with problems, which contributes to ease of implementation and operation.
What's important here is that being "easy to target" and "not being able to operate safely" are not the same thing. In the wp2shell incident in July, WordPress itself fixed the vulnerability and even implemented forced automatic updates. The remaining challenge is to confirm whether the corrected version has been applied to each site and whether there's a system in place to continue necessary updates.
The condition for continued safe use is a "maintenance system"
It becomes dangerous when it's "left unattended"
As the IPA's warning indicates, assuming "it must be updating automatically" poses a risk in site management. Automatic updates are a convenient mechanism, but they may not function properly depending on the environment and settings.
Also, as KUSANAGI explained in their September report, WordPress primarily provides ongoing fixes for the latest version, and providing fixes for older versions is treated as a special measure. If you continue to use an older version, you may not receive fixes for new vulnerabilities in the future. Some companies that provide WordPress maintenance services indicate that sites where updates have been delayed for more than six months are at high risk of their vulnerabilities being exploited.
3 questions to check first
If you want to check the security of your website, please check the following three points first.
1. Is there a designated "maintenance contact" for this site?
It doesn't matter if it's an internal staff member or an external production/maintenance company. Being able to answer 'who is managing it' by name is a good benchmark.
2. Are the WordPress core, plugins, and themes regularly updated, and are backups performed regularly?
It's not enough to say, 'I update the WordPress core, but I don't know about the plugins.' Let's check the update status of the core, plugins, and themes, and whether backups are being made regularly for recovery in case of emergency.
3. Do you have a designated contact person and a rollback procedure in case of problems?
When problems like "the site stopped displaying" or "an unauthorized page was displayed" occur, who should you contact, who will check the situation, and how will it be restored? If possible, it's reassuring to decide in advance "who" "monitors what" "within how many hours of a problem occurring" and "what they will do."
Whether WordPress is dangerous depends not on "whether it's used," but on "whether it's maintained."
It's not a simple matter of "WordPress is dangerous" or "WordPress is safe." What's important is whether you have a system in place to recover when a problem occurs, assuming vulnerabilities will be discovered. First, try answering the following three questions.
- Is there a designated maintenance person?
- Are updates and backups for the core, plugins, and themes being performed?
- Are the contact person and recovery procedure decided in case of a problem?
If there are any items you struggle to answer, that's the "next place to focus" for your current site.
It's impossible to eliminate the risks of WordPress entirely. That's precisely why you need to create a system that doesn't ignore vulnerabilities, assuming they will be found. That's the basic principle for using WordPress safely for a long time.