Law Firm Cybersecurity — Chapter 1

WordPress Security: Your Firm’s Least-Guarded Front Door

The single piece of infrastructure nobody has touched since launch is the one facing the street.

Law Firm Cybersecurity · Chapter 1~8 min read

Why the website is target number one

Roughly 42% of all websites run on WordPress.1 That dominance is exactly what makes it the most thoroughly studied attack surface on the internet. Every weakness that surfaces in the WordPress ecosystem gets indexed, published, and folded into automated tooling within days — tooling that then scans the entire web looking for sites that haven't caught up yet.

Nobody is sitting at a keyboard deciding to target your firm specifically. Bots are knocking on every door on the street, continuously, checking which ones are unlocked. Yours is on the same street.

FIGURE 1 — YOUR SITE, AS AN ADVERSARY READS IT
The login page. A known, predictable URL — the same one on two of every five websites on earth.
The plugin layer. The part nobody updates.
The contact form. Untrusted input, delivered to a human. (Chapter 3.)
The attorney bio pages. Org chart, free of charge.
Uploaded PDFs. Metadata. (Chapter 4.)
The hosting & DNS layer. The keys to all of it.
The guide returns to this map, chapter by chapter.

The counterintuitive part: the danger usually isn't "WordPress"

Here is the finding that reframes the problem.

In 2024, 7,966 new vulnerabilities were disclosed across the WordPress ecosystem — about 22 per day, and a 34% jump over the year before. Of those, 96% were in plugins and 4% were in themes. Seven were in WordPress core itself, and none posed a widespread threat.2

The 2025 numbers went the same direction, harder: 11,334 new vulnerabilities, a 42% increase, still overwhelmingly plugin-driven, with six low-priority issues in core.3

FIGURE 2 — WHERE WORDPRESS VULNERABILITIES ACTUALLY LIVE
  • Plugins 96%
  • Themes 4% — 7,959 in plugins and themes
  • WordPress core 0.09% — 7 of 7,966, shown enlarged
  • 43% exploitable with no login at all
Source: Patchstack, State of WordPress Security in 2025.

Read that again with your own site in mind. The risk almost never lives in WordPress. It lives in the add-ons — the contact-form plugin, the page builder, the SEO tool, the slider, the appointment scheduler, the analytics connector. The things a previous web person installed once, for a reason nobody remembers, and never updated.

Two more numbers make this concrete. Roughly 43% of 2024's WordPress vulnerabilities could be exploited without any login at all — no credentials, no insider, just a request from the open internet.4 And 46% of vulnerabilities in Patchstack's 2025 analysis were not fixed by the developer before the flaw was made public3 — meaning that for a meaningful share of these issues, the exploit is public knowledge while the patch does not yet exist.

An abandoned plugin isn't dormant. It's a standing, published invitation.

What a compromised site actually costs a firm

A hacked website sounds like an IT embarrassment. For a law firm it's a confidentiality problem, because a site is rarely the destination — it's the foothold.

What an adversary does with it:

  • Harvests credentials from your login page, then tries those same credentials everywhere else your people log in (that's Chapter 2).
  • Redirects your prospective clients to a lookalike site, or serves them malware — meaning the harm lands on the people who trusted your firm enough to click (that's Chapter 8).
  • Sends mail as you. A compromised site on your domain is a credible launchpad for phishing aimed at your own staff, your clients, and opposing counsel.
  • Pivots inward toward anything the site touches: the hosting account, the DNS records, the CRM the intake form feeds, the mailbox that receives it.

The profession's own numbers say this isn't hypothetical. In the ABA's 2023 Legal Technology Survey, 29% of responding firms reported having experienced a security breach — and another 19% said they didn't know whether they had.5

What this means for your professional obligations

In the United States

Competence isn't confined to the law anymore. Comment [8] to Model Rule 1.1 folds into the duty of competence an obligation to keep abreast of the benefits and risks of relevant technology.6 Rule 1.6(c) separately requires reasonable efforts to prevent unauthorized access to information relating to the representation of a client.7 A duty of technological competence has now been adopted in 40 states, plus D.C. and Puerto Rico8 — adoption varies: most follow Comment 8, D.C. amended a different comment, and California added it as its own Comment 1.

The ABA's Standing Committee on Ethics and Professional Responsibility has twice built on this: Formal Opinion 477R (2017) on securing client information in electronic communication, and Formal Opinion 483 (2018) on what lawyers must do before and after a breach.9

The critical word in all of it is reasonable. Formal Opinion 483 is explicit that this is not a strict-liability standard — a breach that happens despite reasonable efforts is not itself an ethical violation. The exposure arises where a lawyer fails to make reasonable efforts to avoid or detect the intrusion, and that failure is what causes the breach.9

"We never touched the website" is not a reasonable effort. It's the absence of one.

In Canada

The Federation of Law Societies added commentary to the competence rule in October 2019: a lawyer should develop an understanding of, and ability to use, technology relevant to their practice, and should understand the benefits and risks of that technology — expressly linked to the duty to protect confidential information.10 The provinces have been adopting it since (the paragraph numbering varies by jurisdiction). The confidentiality duty it points back to is a demanding one: strict, owed to every client, and it survives the retainer indefinitely.11

The Canadian commentary is also proportionate by design. It reaches technology that is necessary to your practice and reasonably available to you. Nobody is required to buy enterprise tooling. Keeping the software your public website runs on from going years out of date is squarely inside that line.

What actually fixes this

In priority order, because not all of this is equally urgent:

1. Update on a schedule, not on a scare. Core, plugins, and themes, on a defined cadence, with a staging check so an update never takes the site down. Given how fast disclosure-to-exploit moves, quarterly is no longer a cadence — it's a gap.

2. Delete what you don't use. Every deactivated-but-installed plugin is still code sitting on your server. If a plugin is abandoned by its developer, it will never be patched — that's not a maintenance item, it's a removal item.

3. Put a firewall in front of it. A web application firewall (or virtual patching) is what covers the window between "the flaw is public" and "the developer ships a fix" — the window that, on the numbers above, is open nearly half the time.3

4. Harden the front door. No admin username. Multi-factor authentication on every administrative login. Rate-limit login attempts so credential-stuffing runs die on arrival.

5. Back up somewhere else. Off-site, versioned, and — this is the part people skip — actually restored once to confirm the backup works. An untested backup is a hypothesis.

6. Watch it. Monitoring is how you avoid being in that 19% who don't know. Detection is a named part of the reasonableness standard, not an extra.9

Interactive — your site's exposure, in 60 seconds
Your answers are only stored in your browser, not transmitted to our servers.

How we can help

Everything on that list is recurring, invisible, and unbillable to your clients. It is exactly the work that doesn't get done — not because firms don't care, but because it never becomes urgent until the day it becomes an emergency.

That's the entire reason this service exists. We maintain law firm websites: managed updates, plugin inventory and removal, firewall and monitoring, hardened logins, tested backups. Not a project. A standing arrangement, so that "reasonable efforts" is something your firm can actually document rather than something it hopes was true.

Free external security audit

We'll audit your firm's site from the outside — no access required; we only look at what the public can already see. That's the point.

Your firm's WordPress security checklist

Spencer McLennan
Spencer McLennan is the founder and lead webmaster of LegalWebmasters, and has handled websites, hosting, and security for law firms and professional practices across the United States and Canada since 2007. He holds an MBA, a PCM from the American Marketing Association, and is a graduate student in intelligence studies. He writes the Law Firm Cybersecurity and Law Firm SEO & Design guides. Connect on LinkedIn.

Footnotes

  1. W3Techs, Usage Statistics and Market Share of Content Management Systems (last visited July 2026).
  2. Patchstack, State of WordPress Security in 2025 (2025).
  3. Patchstack, State of WordPress Security in 2026 (2026).
  4. 8,000 New WordPress Vulnerabilities Reported in 2024, SecurityWeek (Mar. 17, 2025).
  5. ABA Legal Tech. Res. Ctr., 2023 Cybersecurity TechReport (2023).
  6. Model Rules of Pro. Conduct r. 1.1 cmt. 8 (Am. Bar Ass'n 2023).
  7. Id. r. 1.6(c).
  8. Robert Ambrogi, Tech Competence, LawSites, lawnext.com/tech-competence (last visited July 2026).
  9. ABA Comm. on Ethics & Pro. Resp., Formal Op. 483 (2018); ABA Comm. on Ethics & Pro. Resp., Formal Op. 477R (2017).
  10. Model Code of Pro. Conduct r. 3.1-2 cmts. [4A]–[4B] (Fed'n of L. Soc'ys of Can. 2019).
  11. Id. r. 3.3-1.

Trusted by professionals like you.

Crease Harman LLP Borders Law Group David Aujla, Immigration Lawyer