In February 2026, the security firm Patchstack published its annual State of WordPress Security report. One number stands out: 11,334 new vulnerabilities were found in the WordPress ecosystem in 2025. That’s a 42% increase on the year before, and the report notes that more high-severity flaws were discovered in 2025 than in the previous two years combined.
Many NHS GP practice websites run on WordPress. If yours is one of them, those numbers describe the weather your website lives in, whether anyone at the practice knows it or not. And in our experience, most practices genuinely don’t know. This post is about how to find out, and what to ask.
What those numbers actually mean
A few figures from the report are worth translating into plain English:
- 91% of the new vulnerabilities were in plugins. WordPress websites gain their features by installing plugins: separate pieces of software, written by thousands of different third parties, each one running on the same site as your patient-facing pages. Every plugin is somebody else’s code and somebody else’s security record.
- 46% of vulnerabilities were not fixed in time for public disclosure. In other words, when the world learned about nearly half of these holes, no fix yet existed. Sites running the affected plugin were simply exposed, waiting.
- The median time from disclosure to first exploit attempt was five hours for the most heavily targeted flaws. Attacks are automated. Nobody is choosing your practice; a script is scanning every WordPress site on the internet, including yours.
To be clear, these are figures for the whole WordPress ecosystem, not for GP websites specifically. But a WordPress site doesn’t know it belongs to a GP practice. The scripts scanning it don’t either.
Why this is the practice’s problem
It’s tempting to file all of this under “my provider’s job”. Legally, it doesn’t work that way. As we covered when we looked at why building your own website is a false economy, a practice remains legally responsible for its website even when the work is outsourced. The practice is the data controller. If a compromised site leaks patient information or serves malware to patients, the headline has the practice’s name in it, not the plugin author’s.
And this isn’t hypothetical for the NHS. In 2026, NHS England issued a critical cyber alert about cPanel and WHM, infrastructure used by website suppliers across the UK, and practices everywhere had to scramble to find out whether they were affected. The practices that struggled most were the ones who didn’t know what their website ran on in the first place.
Three questions to ask your website provider
You don’t need to be technical to take control of this. You need three answers, and any provider worth having can give them without hesitation.
- “What platform does our website run on?” If the answer is WordPress, that isn’t automatically a crisis. But it makes the next two questions urgent rather than optional.
- “How many plugins does it use, and what are they?” Nine in ten new WordPress vulnerabilities live in plugins. A provider who can’t list yours is telling you something important about how closely your site is being looked after.
- “Who patches them, and how quickly?” With exploit attempts starting within hours of disclosure, “we update things monthly” is not the comforting answer it sounds like. Ask what happens when a critical flaw is announced at 5pm on a Friday.
The pattern to watch for isn’t any single answer. It’s whether your provider knows the answers at all. Instant, specific replies mean your website has an owner. Vague ones mean it has a landlord.
If you don’t know where to start
If you’d like an independent picture of where your website stands today, our free website audit checks any UK GP practice website across six areas, including security, and sends you a plain-English report. It’s free, there’s no obligation, and it works whoever built your site.
Our answer, for the record
Practices sometimes ask how many of these vulnerabilities affect Tree View Designs websites. The answer is zero, and it always has been. No Tree View Designs website has ever run WordPress, a plugin, or a shared theme. Our platform and CMS are custom-built, and always have been, rebuilt generation after generation since 2009, with every line of code written, patched and controlled by the team you talk to. The 11,334 vulnerabilities in Patchstack’s report are somebody’s emergency. They have never once been ours, or our practices’.
If you’ve asked your provider the three questions and the answers left you uneasy, or you simply want to talk through what good looks like, get in touch. We’re always happy to give you an honest read on where you stand.