Bottom line: Security leaders should prioritize vulnerability scanning and breach recovery planning for WordPress sites.
What's happening: Melapress surveyed 319 WordPress professionals, who reported experiencing at least one known security incident, with 62% responsible for building and running the sites.
What to do: Focus on critical vulnerabilities like Heartbleed (CVE-2022-4289, CVSS score 4.9) and Log4Shell (CVE-2021-21211, CVSS score 9.3), and create a breach recovery plan with critical asset lists and trusted vendors.