Running an old version of WordPress is one of the most common reasons sites get hacked. Updates aren't optional maintenance — they're active security patches.
When a WordPress security release comes out, the vulnerability it patches is made public — often within days. That means every site still running the old version is now a known target. Automated scanners catalogue vulnerable WordPress installs across the internet and attack them at scale. The gap between "update released" and "attacks begin" is measured in hours, not weeks.
The WordPress 2.8.x series had several serious vulnerabilities patched in rapid succession through 2009 and into 2010. Sites that didn't keep pace were compromised in bulk — not by skilled attackers targeting them specifically, but by automated tools running the same exploit against thousands of sites simultaneously.
The goal isn't usually to deface your homepage. A compromised site is more valuable to attackers if you don't know it's compromised. Common outcomes:
By the time you notice something is wrong — a Google warning, a hosting suspension, a customer complaint — the damage has often been running for weeks.
Unlike today, WordPress didn't have a one-click update system until version 2.7 (December 2008). Even then, many hosting environments required FTP credentials to apply updates, and plenty of site owners had set up WordPress and never looked at it again.
The manual update process — downloading the zip, uploading via FTP, running the database upgrade script — was enough friction that a large portion of sites never updated at all. By mid-2010, there were significant numbers of live WordPress sites running versions two or three major releases behind, with publicly known exploit code available for all of them.
The risk of an update going wrong is real but manageable. Before every update:
With a fresh backup in hand, a WordPress core update is low risk. An incompatible plugin can usually be deactivated to restore a working site while you wait for an updated version. A working backup means the worst case is always recoverable.
WordPress version numbers follow a pattern: 3.0, 3.0.1, 3.0.2, and so on. The minor versions (3.0.1, 3.0.2) are almost always security or bug fix releases. They should be applied immediately with no hesitation — they don't add features that could break things.
Major versions (3.0 to 3.1) may include new features and database changes. The compatibility risk is slightly higher, but the security improvements are more significant. Apply them within a few days of release, not months.
There's no such thing as a perfectly secure website, but the sites that don't get hacked are overwhelmingly the ones that are kept current. Attackers are lazy by design — they run automated tools against millions of sites and harvest the easy ones. A site running the current WordPress version with updated plugins is simply not in that category.
The single most effective thing you can do for your WordPress site's security is also the simplest: keep it updated. Not quarterly. Not when you remember. Every time a new version is released.
At DownUnder WP, WordPress core, plugin, and theme updates are available with one click from your dashboard. You control when they run — no surprises, no auto-updates you didn't ask for.
Australian WordPress hosting from $5/month
Your own containerised environment on Australian NVMe servers. Simple, fast, and genuinely cheap.