HomeBlog › Website Repair

WordPress Hacked Perth — Why It Happens and How to Stop It

17 June 2026·4 min min read· Website Repair

Your WordPress site was hacked at 2am on a Wednesday. You didn't find out from a monitoring alert. You found out when a client rang to say Google Chrome was throwing a red security warning on your URL. By the time you logged in, Google had already flagged the site, your organic rankings were in freefall, and the malware had been sitting there long enough to do real damage. If you're searching "wordpress hacked perth" right now, you're either already in that situation or you're smart enough to want to avoid it. Either way, this post covers exactly how it happens and what you do to stop it.

The uncomfortable truth about most WordPress hacks is that they aren't sophisticated. There's no elite hacker specifically targeting your Fremantle café or your Osborne Park accounting firm. It's automated tools scanning millions of WordPress installs simultaneously, looking for the same predictable weaknesses. Bots don't care that you're a small business. They just care whether your site is an easy target.

Here are the nine most common ways that happens — and the specific action that closes each one off.

1. Outdated Plugins

Plugins are the most common entry point for WordPress compromises, full stop. When a security vulnerability is discovered in a plugin, the developer releases a patch. That patch is also, effectively, a public announcement of exactly what the vulnerability was. Any site still running the old version is now a known, documented target.

The ACSC's patch management guidance is clear on this: critical patches should be applied within 48 hours. Most Perth business owners are running plugins they last updated six months ago.

What to do: Set plugins to auto-update where the plugin is stable and well-maintained. For anything where an update could break functionality — WooCommerce, page builders, payment integrations — check out how to perform WordPress updates safely before you click update. Do it in a staging environment first, not live.

It's also worth running a WordPress plugin security audit periodically. You may have plugins installed that you've forgotten about, haven't used in years, and haven't been maintained by their developer in a very long time.

2. Outdated or Inactive Themes

Same logic as plugins, with one extra twist: inactive themes. You installed a theme to test it, switched to something else, and left the old one sitting there deactivated. It's still loaded on your server. It still has vulnerabilities. It still gets exploited.

Attackers don't need a theme to be active to use it as an entry point — just present.

What to do: Delete every theme you're not actively using. Keep your active theme updated on the same schedule as your plugins. If you're running a child theme, make sure the parent theme is also being maintained. If the parent theme hasn't had an update in two years, that's a red flag worth acting on.

How to Perform WordPress Updates Without Breaking Your Site

If the reason you're not updating is fear of breaking things — which is a legitimate concern — the answer is a proper update process, not skipping updates altogether. A safe WordPress update workflow covers backups before updates, staging environments, and what to check afterwards. Avoiding updates because they might break something is swapping a certain risk for a smaller one.

3. Weak or Reused Passwords

Yes, "Password123" counts as a password. No, adding an exclamation mark doesn't make it secure.

Credential stuffing attacks use lists of username and password combinations leaked from other breaches. If you've reused the same password across multiple accounts — your WordPress admin, your email, your accounting software — and any one of those services was breached, every other account using that password is now compromised too.

What to do: Use a unique, randomly generated password for your WordPress admin account. A password manager handles this without you needing to memorise anything. Minimum 16 characters, no dictionary words. While you're at it, audit every user account in your WordPress install and remove any that don't need to be there.

4. No MFA on wp-admin

Even with a strong password, your admin login is a single point of failure. Brute force tools and credential stuffing don't care how strong your password is if they can keep trying indefinitely.

Multi-factor authentication means that even if an attacker gets your password, they still can't log in without the second factor — typically a code from an authenticator app.

What to do: Install a reputable MFA plugin and enforce it for all admin-level accounts. This is non-negotiable. If you want to understand how MFA configuration works more broadly, our MFA configuration guide for Perth businesses covers the setup in detail.

5. Nulled Plugins and Themes

This one deserves a longer mention because the risk is so badly underestimated.

A "nulled" plugin or theme is a paid product that someone has cracked and distributed for free. They're easy to find, and the pitch is obvious: why pay for something when you can get it free?

Here's what you're actually getting: a modified version of the plugin, almost always with backdoors or malicious code already embedded. You install it, it appears to work, and in the background it's either already communicating with a remote server or waiting for an instruction to do so.

What to do: Don't use nulled software. Ever. If a premium plugin or theme is out of your budget, find a legitimate free alternative from the official WordPress repository. The money you save on a nulled theme is nothing compared to the cost of cleaning up a compromised site — or explaining to your clients why your contact form was harvesting their data.

Need a hand with this?

Perth IT Care can sort it out for you. No jargon, no runaround.

Get in touch