The problem isn't WordPress, it's who steers it

🇫🇷 Lire en français : Le problème n'est pas WordPress, c'est qui le pilote
The problem was never WordPress. It is the website launched with no technical oversight. Across 653 overseas sites measured by our observatory in August 2026, 44 % run on WordPress, and 59 % of those WordPress sites send no HTTP security header at all. After a summer of back-to-back flaws, it is time to name the real cause: nobody is steering.
Key points
- WordPress powers 44 % of the 653 sites measured by the Kimoun observatory in August 2026, which is 7 out of 10 among those where a CMS could be identified.
- Summer 2026 delivered critical flaws one after another: wp2shell in the WordPress core in July, a dozen vulnerabilities patched on 6 August, Elementor Pro and Forminator in mid-August.
- 59 % of the WordPress sites measured send none of the five HTTP security headers tested, against 15 to 27 % for the other sites in the panel.
- Modern static architectures cut the attack surface by design, but they replace neither content, nor structure, nor someone steering the infrastructure.
The apparent ease of WordPress put website building in everyone’s hands. That is good news for the democratisation of the web, and very bad news for the security of those who have no idea what they are exposing. — Olivier Watte, known as Oliver · founder of Kimoun
Why did so many WordPress sites fall this summer?
Tip
In eight weeks, WordPress took a critical flaw in its core, a salvo of patches in early August, then three major plugin vulnerabilities, exploited within hours.
On 17 July 2026, WordPress shipped emergency patches for wp2shell, a chain of two core flaws allowing full control of a site with no account, no password and not a single plugin involved. I analysed that flaw when it was published, then documented the 72 hours between the patch and the first attacks.
What followed did not slow down. On 6 August, version 7.0.3 fixed a dozen further vulnerabilities, including a remote code execution reported by France’s CERT-FR. In mid-August, three major plugins followed: Elementor Pro (CVE-2026-32475, severity 9.0/10, PHP file upload through the forms module), Forminator (CVE-2026-15748, roughly 300,000 sites exposed) and User Profile Builder (CVE-2026-15826, administrator account takeover on more than 40,000 sites).
The most revealing case remains that of the vendor BdThemes: seven of its plugins were used to install rogue administrator accounts without a single plugin file being modified: the attackers poisoned an advertising data feed loaded into the dashboard. A supply chain attack, cousin to the one that hit npm on 4 August.
Does AI explain the acceleration?
AI is often invoked to explain this acceleration, and the trend is real: researchers and attackers alike now tool their analysis with models, which shortens the delay between patch and exploitation. But AI does not explain the essential part. The WP-SHELLSTORM campaign, documented in July, installed more than 17,000 backdoors by exploiting 27 flaws that were already known and already patched: no zero-day, no feat of skill. Just a global estate of sites nobody maintains.
What does our observatory measure on sites here?
Tip
59 % of the WordPress sites measured by the Kimoun observatory send no HTTP security header, against 15 to 27 % for other sites (August 2026).
The Kimoun observatory measures the digital maturity of 665 overseas sites: agencies, businesses, local authorities, associations. This panel is not a random sample of the overseas web, but it provides a snapshot nobody else takes. The figures quoted below vary from one measurement to another: not all of them complete on every site, and I would rather report the number actually measured than a rounded total. WordPress powers 289 sites out of 653 measured, that is 44 %, and 70 % of the sites where a CMS could be identified. Across the 143 Guadeloupean sites in the panel, the proportion is comparable: 41 %.
Headers, DNS, PHP: what the readings show
What the measurements reveal is less the dominance of WordPress than what comes with it. 39 % of the 647 sites measured send none of the five HTTP security headers tested (Content-Security-Policy, Strict-Transport-Security, X-Frame-Options, X-Content-Type-Options, Referrer-Policy), the settings that protect a visitor against session hijacking, content injection or clickjacking. And the split is telling: on the WordPress side, total absence affects 59 % of sites; on other CMS and sites with no detected CMS, between 15 and 27 %.
DNS tells the same story, with an instructive nuance. WordPress sites more often have an SPF record than the others, an effect of shared hosts that preconfigure the zone. But 72 % of the 665 domains measured remain spoofable by email: no enforcing DMARC policy is applied. The host’s default configuration stops exactly where the decision begins, and nobody takes the decision.
Warning
Even if your domain sends no email at all, an unlocked DNS lets anyone send messages posing as your brand. In our panel, two thirds of the domains with no mail server have set no lock whatsoever: no SPF, no DKIM, no DMARC.
Technical debt completes the picture: among the 153 sites in the panel where the PHP version is readable, 35 % run on an end-of-life version, with no security patches since 31 December 2025 at the latest.
What does a site with nobody steering look like?
Note
Last week, someone showed me with genuine pride the website of a small local organisation, built by a graphic designer and a friend. The site is good-looking. A few minutes of technical reading revealed: no security header, a PHP version end-of-life since December 2025, the phpinfo() page publicly exposed, 78 plugins installed, including five security plugins stacked on top of each other, and one plugin pulled from the official repository after its publisher was compromised. Not to mention a heading hierarchy in disarray, with several H1 tags, which directly penalises its search ranking.
That site is not an exception, it is an archetype. Five security plugins coexisting means five locks fitted to a door left open: each one adds code, therefore attack surface, without fixing the underlying problem. Headings in disarray are the signature of a page built in Elementor by someone who judges by the visual result, which is their job, without knowing the structure of a web document, which is not. A good-looking site is not a good site: one is visible on screen, the other is verified in the code, the headers and the DNS.
I blame neither the designer nor her client. The business model of WordPress and its themes rests precisely on that promise: launch a professional website without a technical professional. The summer of 2026 has presented the bill for that promise.
Are static sites only good for blogs?
A static site, generated by tools such as Hugo or Astro, serves precomputed pages: nothing executes on the server on each visit. No PHP to maintain, no database to protect from injection, no public back office to defend against brute force. wp2shell was exploitable on a bare WordPress install; the equivalent simply does not exist on a static site, because there is nothing to execute.
The received idea that sticks to these tools, “fine for a blog”, is ten years out of date. Modern templating handles multilingual content, taxonomies, structured data, galleries and FAQs: kimoun.com, bilingual and entirely static, demonstrates it daily. Interactive functions go through dedicated services: a quote form wired to a sending gateway in Python or Go, a newsletter sign-up connected to Brevo, simple payment collection through a payment provider. Each brick lives in its own perimeter, tiny and auditable, the opposite of the 78-plugin site where chat, video calls and payments all share one database.
Editing, publishing, paying: the dynamic functions
Editing without technical skills exists too: lightweight admin interfaces let you change text and images from a browser, phone included, without ever exposing an admin panel on the site’s own server. On performance, precomputed pages clear the Core Web Vitals thresholds without stacking four caching and image optimisation plugins. On budget, hosting costs a few euros a month, and the “WordPress maintenance” retainer disappears, which changes the total cost of a website.
Let us be honest about the limit: a full shop, a member area, a training platform remain genuine application needs, and a dynamic CMS still makes full sense there, provided it is managed by a professional who patches, monitors and backs up. The architecture choice is a technical decision, not a box ticked in a template.
Is an AI-generated static site enough?
The market is confirming this shift from dynamic to static. According to W3Techs, the WordPress share is falling in a sustained way for the first time: from 43.2 % of sites in December 2025 to 41.2 % in July 2026, while the “no detectable CMS” category, which covers static sites, modern frameworks and AI-produced sites, rises from 28.6 % to 30.4 %. A growing share of these new static sites is generated with AI assistance, and the average result is decent: cleaner code, correct structure, respectable performance.
But that production line has a downside: uniformity. Technically correct sites, interchangeable, with nothing that lets Google or ChatGPT tell them apart from their competitors. What distinguishes a site, in 2026 as in 2006, comes down to three things: content (text that says something, images that show your reality), structure (internal linking, page hierarchy, structured data) and a steered infrastructure (locked DNS, headers in place, hosting under control). The same fundamentals as ever, which AI does not deliver on its own, but which it serves very well when expert supervision frames it.
I welcome this double realisation: users discovering the limits of the WordPress reflex, and communication professionals understanding that a web project has a technical dimension, not as an option, not at the end, but from the design stage onwards. The local web will be all the better for it.
Sources
- CERT-FR — Alert CERTFR-2026-ALE-007, wp2shell vulnerabilities (in French)
- CERT-FR — Advisory CERTFR-2026-AVI-0979, WordPress 7.0.3 (in French)
- The Hacker News — Elementor Pro, CVE-2026-32475
- SecurityWeek — Forminator, 300,000 sites exposed
- Infosecurity Magazine — BdThemes plugins compromised through a poisoned feed
- ITdaily — WP-SHELLSTORM campaign, 17,000 webshells (in French)
- W3Techs — CMS market share
- Kimoun Observatory — panel measurements, August 2026