In 2025, security researchers identified 11,334 new vulnerabilities in the WordPress ecosystem, a 42% increase over the prior year (Patchstack, State of WordPress Security in 2026). Of those, 91% were found in third-party plugins (the add-on software that powers forms, galleries, SEO tools, and other features on a WordPress site), not in WordPress core. WordPress itself had only six core vulnerabilities in 2025. The risk is not the platform. The risk is what gets added to it and who is paying attention after it is built.
For law firms, this problem compounds in ways that do not apply to most businesses.
The economics of scale-based attacks
Automated bots do not select targets based on firm size, prestige, or practice area. They scan the internet for recognizable patterns in how a WordPress site is configured. When they find a site running outdated or vulnerable software, they test known exploits.
The math works in the attacker’s favor. According to Patchstack’s 2026 research, the time from vulnerability disclosure to first mass exploitation is measured in hours, not days or weeks. Not days. Not weeks. Five hours. By the time a plugin developer issues a patch, automated scanners have already identified and begun targeting every site running the vulnerable version.
Forty-three percent of WordPress vulnerabilities discovered in 2025 required no authentication to exploit (Patchstack, 2026). An attacker does not need a login. They do not need credentials. They need a plugin that has not been updated and a site no one is watching.
Why plugins are the real exposure
Most law firm websites accumulate plugins over time. A form builder from the original developer. A speed optimization plugin added later by someone else.
An SEO tool that was installed three years ago and never removed. A gallery plugin for a page that no longer exists. Each plugin is an independent piece of software maintained by an independent developer. Each one requires its own updates, its own security patches, its own attention.
In a single week of January 2026, SolidWP tracked 333 new vulnerability disclosures across the WordPress ecosystem. A significant portion had no available patch at the time of disclosure (SolidWP, January 2026). That means many newly discovered vulnerabilities were public knowledge with no fix available. Every site running those plugins was exposed with no immediate remedy.
Patchstack’s 2026 research found that the majority of plugin developers contacted about vulnerabilities did not issue a patch before public disclosure. This is not a failure of WordPress. It is a failure of maintenance.
What makes law firms a distinct target
A compromised retail website is a business problem. A compromised law firm website is a different category of problem entirely.
Law firm websites collect intake forms containing names, contact information, and descriptions of legal matters. Depending on how those forms are configured, submissions may include information that falls under attorney-client privilege or, at minimum, the protections owed to prospective clients under ABA Model Rule 1.18.
According to the 2024 ABA Cybersecurity TechReport, 36% of law firms reported experiencing a security incident in the prior year. BakerHostetler’s 2026 Data Security Incident Response Report, which drew on more than 1,250 incidents handled in 2025, found that law firms experienced a near-doubling of ransomware incidents over the prior year. The average initial ransom demand across all industries spiked 70% to $4.2 million. One ransomware group targeting law firms specifically made demands ranging from $500,000 to $21 million.
The ABA has addressed these obligations directly. ABA Formal Opinion 477R establishes that lawyers must make reasonable efforts to ensure that communications with clients, including those transmitted through a firm’s website, are secure. ABA Formal Opinion 483 specifies a lawyer’s obligations after a data breach or cyberattack, including the duty to monitor for breaches, to take reasonable steps to stop them, and to notify affected clients.
The professional obligation is clear. The question is whether the firm’s website infrastructure reflects it.
The three issues we find most often
When we assess law firm websites, the same patterns appear repeatedly.
Outdated software. WordPress, its plugins, and its themes require regular updates to patch known vulnerabilities. These updates are released on a rolling basis. When they are not applied promptly, the vulnerability remains open and publicly documented. Deferred updates are the leading cause of WordPress security incidents.
Default login paths. WordPress installations ship with a predictable, publicly known login URL. Most firms have never changed it. Changing it takes minutes. Leaving it unchanged gives every automated password-guessing attack a known target.
Plugin accumulation. Law firm websites collect plugins over time, often from multiple vendors across multiple redesign projects. Many perform overlapping functions. Each one is an additional surface that requires monitoring. In most cases, no one is monitoring them.
What resolution looks like
The fix does not require a new website. It does not require an IT overhaul. It requires someone paying consistent, competent attention to the site you already have: regular software updates, protected login access, active monitoring, daily backups, and periodic security reviews.
WordPress is not the wrong platform for a law firm. Unmanaged WordPress is.
The first step is knowing where you stand.
MPF members can request a complimentary website security and performance audit. Results are delivered within one business day, with an optional call to walk through the findings in plain language. No technical background required.
Sources cited in this article:
- W3Techs, WordPress usage statistics, 2026
- Patchstack, State of WordPress Security in 2026 (published February 2026)
- BakerHostetler, Data Security Incident Response Report, 2026
- SolidWP, Weekly Vulnerability Reports, January 2026
- ABA Cybersecurity TechReport, 2024
- ABA Formal Opinion 477R (Securing Communication of Protected Client Information)
- ABA Formal Opinion 483 (Lawyers’ Obligations After an Electronic Data Breach or Cyberattack)
- ABA Model Rule 1.18 (Duties to Prospective Client)