Piperic
Security Report
PricingToplistsBrowse free →
🛡️ The WordPress Security Report · July 2026

🇨🇳 China: 5,000 websites run software with a known security flaw

We analysed 59 million websites with the help of AI. The result is dismal.

We reached 651,900 live websites in China. 17,416 of them run WordPress, and where we could see which version (11,061 sites), 5,000 — 45.2% — carry a plugin or theme with a publicly known security flaw. It is a floor: sites that hide their version are not counted at all. What it shows is how far behind these systems are kept.

Analysis of live, content-validated websites · vulnerability data from Wordfence Intelligence · snapshot 2026-07-25 · by Piperic

Share:XLinkedIn

45.2%
run a known-vulnerable component
34%
run a component exploitable WITHOUT any login
Of the known vulnerabilities we matched, this counts only those that require no authenticated account (CVSS “Privileges Required: None”) — the subset an anonymous attacker could reach.
7%
run a critical (CVSS 9+) flaw

We did not attack a single website

This report was produced without trying a password, scanning a port, probing a login form or sending one request an ordinary browser would not send. We asked each site for its homepage — exactly the way your browser does when you type the address — and read what came back. Everything below is what is visible from the outside, in China and in 58 other countries.

Why this matters more this year than last

Finding an outdated component on a website used to be work: you had to look, recognise, cross-check. That is the part that has changed. Reading a page, identifying a version and matching it against a vulnerability database is now a task a machine performs continuously, at the scale of the whole web. Of the China WordPress sites we could measure, 34% run at least one flaw rated as requiring no privileges at all — no account, no password. That is not the hardest category to exploit. It is the easiest one to automate.

The threat is not that someone is targeting your website. It is that nobody has to.

Where China stands in the world

Share of measured WordPress sites running a known-vulnerable component — lower = more up-to-date. China ranks #57 of 59 countries.

🇻🇳 Vietnam83.6%🇲🇦 Morocco76.9%🇹🇷 Turkey75.7%🇹🇭 Thailand74.1%🇧🇾 Belarus73.9%🇭🇰 Hong Kong73.6%🇮🇱 Israel73.3%🇬🇷 Greece73.1%🇨🇳 China45.2%

Neighbours shown for context. Full ranking in the data download.

How China compares to the world

China's WordPress web measured against the global average — and its exposure to an end-of-life front-end library that stopped receiving security fixes in 2016.

45.2%
of China's sites vulnerable
57.8%
global average
76.2%
on end-of-life jQuery 1.x

The whole web — not just WordPress

These measures apply to every live China website we analysed. They need no version detection, so they carry no selection bias.

61.6%
still serve without HTTPS
34.3%
load third-party JavaScript unchecked (no SRI)
3,714
pages ask for a password over an unencrypted connection
2.7%
mix insecure resources into a secure page

Global finding — measured across all 59 countries, not China alone — We checked where those password forms actually send the password. Across the study, 89.1% of them submit it in plain text as well — the form posts back to the same unencrypted page. Only 5.1% post to an encrypted address, and even there the page itself can be rewritten in transit, because it arrived unprotected.

Platforms past their end of life

Share of each platform's China sites still on a release line for which the vendor has stopped shipping security fixes.

PlatformSitesOn an unsupported line
Joomla88161.1%
Drupal72219.5%

End of support: Joomla 3.x — August 2023 · Drupal 7 — January 2025 · Magento 1 — June 2020.

Global finding — measured across all 59 countries, not China alone — Across the whole study, visible defacement is 45.5× more prevalent on Joomla sites than on WordPress sites — while injected spam, on the very same pages, is only 1.3× more common, so the gap is specific to break-ins. This is a snapshot: it measures how many sites are visibly defaced right now, not how often they are broken into.

The most common vulnerable components in China

Share of measured China WordPress sites running each plugin or theme in a version with a known vulnerability.

Contact Form 77.92%Slider Revolution7.88%WooCommerce5.21%Astra (theme)4.41%WPBakery Page Builder4.14%Elementor Pro4.06%Elementor2.22%Elementor Header & Footer1.96%Essential Addons for Elementor1.91%Tablepress1.26%LayerSlider1.22%Blocksy1.07%Dt The71.06%Sitepress Multilingual Cms1%Wpforms Lite1%

The most-used plugins — and how often they're outdated

Among China sites that run each of these popular components, the share on a version with a known vulnerability. Some stay current; page-builders and sliders lag.

Elementor13%Contact Form 746%WooCommerce46%Slider Revolution97%Elementor Pro52%Astra (theme)67%WPBakery Page Builder65%Hello Elementor22%Zibll0%Wp Pagenavi0%Blocksy49%Wcboost Variation Swatches0%Elementor Header & Footer100%Wcboost Products Compare2%Wcboost Wishlist0%

The split follows one line: how the component got there. Components installed directly — listed in the admin panel, with an update button next to them — sit at the bottom of this list. Components that arrive bundled inside a purchased theme, where the owner may never see them listed at all, sit at the top. The risk is not the plugin you chose; it is the one you never knew you installed.

How severe are the exposures?

Of China sites running a vulnerable component, the worst-case severity (CVSS) present.

Critical (CVSS 9.0–10)15.4%High (7.0–8.9)40.4%Medium (4.0–6.9)44.2%Low (<4)0%

Which industries run the most vulnerable components

Share of measured China WordPress sites with a known-vulnerable component, by industry.

SectorSitesVulnerable
Technology And Computing31129.9%

One operator, 15,852 websites — and it only wakes up on phones

The same implant sits on 15,852 of the homepages we analysed, calling 2 attacker-controlled hosts and sending an identical hard-coded campaign ID from every one of them: this is a single operation, not a coincidence. The code first checks whether the visitor is on a desktop computer, and stays silent if so. On a phone it opens a channel to the operator's server and runs whatever that server sends back, inside the visitor's browser — so what actually happens is decided remotely, at the moment of the visit. In two thirds of the copies a random gate limits this to roughly every third visitor: another way to stay unnoticed.

China: we measured 4,242 affected websites.

⚠ These are not compromised businesses, and we do not count them as such. We profiled the sites carrying this code: 88% are Chinese-language adult, pirate-streaming or margin-trading sites and 99.8% run no recognisable content management system. It looks like a network monetising its own mobile traffic. We report it because the technique is what matters: it is the same evasion a real attack campaign would use, and it is invisible to desktop checks. Three quarters of the affected sites worldwide run on generic domains (.com, .net) that cannot be attributed to any country, so national counts are a floor, never a total. And the implant reacts to the visitor's device, not to the website's country.

Signs of compromise

Conservatively detected indicators on China sites. Every figure is a LOWER BOUND — we only count what we can identify with high confidence, and we never name an individual website.

59
carry injected hidden link spam
4
show defacement text

We profiled who carries these signals before publishing them: 74.2% run a recognisable content management system and 46% publish a phone number or an email address. These are working businesses with customers — a dermatology practice, a law firm, a charity — not abandoned domains. The front page of each one is quietly working for someone else.

⚠ The implant we found most often runs only for a share of mobile visitors and opens a connection to an attacker-controlled host, which can then execute arbitrary code in the visitor's browser — a design that deliberately evades desktop security scans.

Servers leaking their own internals

China sites whose homepage prints server-side error messages or internal file paths — information that helps an attacker map the system.

340
print PHP or database errors on the homepage
115
expose server file paths

Check your own website

Free, no signup — see what our index knows about any site:

For journalists — press kit

“The headline vulnerabilities make the news; the quiet reality is that most of China's WordPress web runs a component with a long-known, unpatched flaw — usually a premium plugin bundled into a theme that no one ever updates,”
— said Attila Rácz-Akácosi, founder of Piperic.

How to cite: “According to Piperic's WordPress Security Report (2026-07-25), 45.2% of measured China WordPress sites run a component with a known vulnerability…” — link to this page.

Download the country dataset (JSON) Global rankings dataset

Methodology

Sample: measured China WordPress sites (ccTLD-based assignment) where at least one plugin/theme version was readable from the homepage. Plugin/theme versions are cross-referenced against the Wordfence Intelligence vulnerability database (CVE-anchored). This measures update hygiene — running a version for which a vulnerability was disclosed — not exploitability. Homepage-only detection sees front-end components, not back-end plugins. All figures are aggregate; no individual site is identified. Snapshot 2026-07-25 (frozen). Vulnerability data © Wordfence Intelligence, MITRE where applicable.

Press contact: press@piperic.com · Data: Piperic Business Intelligence

Every number on this page is reproducible from the public dataset above.

Country reports

🌍 Worldwide🇩🇪 Germany🇳🇱 Netherlands🇬🇧 United Kingdom🇷🇺 Russia🇫🇷 France🇧🇷 Brazil🇨🇭 Switzerland🇦🇺 Australia🇵🇱 Poland🇯🇵 Japan🇸🇪 Sweden🇮🇹 Italy🇨🇦 Canada🇪🇸 Spain🇧🇪 Belgium🇦🇹 Austria🇨🇿 Czechia🇸🇰 Slovakia🇩🇰 Denmark🇮🇳 India🇨🇴 Colombia🇬🇷 Greece🇳🇴 Norway🇭🇺 Hungary🇫🇮 Finland🇲🇽 Mexico🇪🇪 Estonia🇳🇿 New Zealand🇨🇱 Chile🇿🇦 South Africa🇷🇴 Romania🇮🇱 Israel🇦🇷 Argentina🇮🇪 Ireland🇺🇦 Ukraine🇻🇳 Vietnam🇵🇹 Portugal🇹🇷 Turkey🇱🇹 Lithuania🇨🇳 China🇷🇸 Serbia🇮🇩 Indonesia🇸🇬 Singapore🇹🇼 Taiwan🇰🇷 South Korea🇸🇮 Slovenia🇭🇷 Croatia🇧🇾 Belarus🇱🇻 Latvia🇱🇺 Luxembourg🇦🇪 United Arab Emirates🇭🇰 Hong Kong🇹🇭 Thailand🇮🇸 Iceland🇧🇬 Bulgaria🇳🇬 Nigeria🇲🇦 Morocco🇱🇮 Liechtenstein