New research from web hosting provider 20i found that most WordPress websites around the world, including in the United States, are running old versions of the software instead of the newest, more secure release. This matters because hackers have gotten better at using software weaknesses to break into websites, and old versions can be missing fixes for problems that are already publicly known. The takeaway is that keeping WordPress core files, plugins and themes updated closes doors that attackers already know how to open.
Widespread outdated software across the WordPress ecosystem
More than 16.59 million WordPress websites in the United States were running software below version 7.1 at the time of analysis, according to research published by web hosting provider 20i today. The company's data, drawn from an examination of over 18.8 million live WordPress sites in the U.S. alone, found that 87.86 percent of American WordPress installations had not moved to the platform's latest and most secure release.
The figures form part of a broader global study spanning more than 44 million WordPress websites, in which 20i concluded that 87.62 percent of sites worldwide, representing over 38.99 million websites, remain on versions below WordPress 7.1. WordPress 7.1 became available on August 19, 2026, and the update gap identified by 20i reflects the period immediately following that release, when adoption of the newest version was still building.
Lloyd Cobb, director at 20i, framed the stakes of the update gap in a statement accompanying the research. "With hackers able to act much quicker as AI changes the threat landscape, keeping software up to date is more important than ever. Being one major version behind might not seem like much, but if important security fixes haven't been applied, it can leave a website exposed to issues that attackers already know how to exploit," Cobb said.
Cobb also addressed the practical tension facing website operators between security and stability. "The answer isn't necessarily to install every major update the moment it's released, as businesses need to know an update won't affect how their site works, particularly if it handles sales. What's important is having a process in place so updates are tested and dealt with rather than continually pushed back," he said. "Managed WordPress hosting includes automatic updates that can take care of many fixes, while major changes should be tested before going live and backed up so they can be rolled back if something goes wrong. That gives businesses a much better chance of staying current without putting the day-to-day running of their site at risk."
Methodology behind the figures
20i built its analysis using BuiltWith, a technology-tracking service, to examine the content management system version running on live WordPress websites globally. Any site operating below WordPress 7.1 was classified as outdated for the purposes of the research. The company also segmented its business-size analysis using available annual revenue data, sorting organizations into five categories: micro-business ($100 to $10,000), small business ($10,000 to $1 million), SMB ($1 million to $10 million), mid-market ($10 million to $100 million) and enterprise (more than $100 million).
A pattern of security releases in quick succession
The update gap identified by 20i did not emerge in isolation. WordPress issued three separate security releases in less than four weeks during July and August 2026, a pace that underscores how frequently the platform has needed to patch newly discovered flaws. WordPress 7.0.2 addressed one critical and one high severity security issue. That release was followed by further security fixes bundled into version 7.0.3, and then by another round of patches in version 7.0.4. WordPress recommended that users update their sites immediately following each of these releases.
The severity of some of these issues prompted WordPress to take a more aggressive stance than usual. According to 20i's research, WordPress enabled forced automatic updates for sites running versions affected by the critical vulnerabilities addressed in 7.0.2, given the seriousness of the flaws involved. Forced updates of this kind are typically reserved for security issues that WordPress considers too dangerous to leave to individual site owners' discretion.
The scale of exposure tied to these specific releases is considerable. In 20i's dataset, approximately 24.79 million outdated websites, around 63 percent of the entire outdated group identified in the research, were running either WordPress 6.9 through 6.9.4 or WordPress 7.0 through 7.0.1. These are precisely the version ranges affected by the vulnerabilities that were subsequently addressed through the mid-2026 security releases, meaning tens of millions of sites sat within the window of known exposure before patches were applied.
Version distribution reveals depth of the lag
While WordPress 6.x remains the single most common generation in active use, accounting for 68.11 percent of all WordPress sites analyzed globally, or more than 30.3 million websites, the research also surfaced a long tail of installations running considerably older software. The WordPress 6.x generation began with version 6.0 in May 2022, meaning a majority of the web's WordPress installations are running software that predates the current release by roughly four years.
Beyond the 6.x generation, 20i's global figures show around 1.12 million sites still using WordPress 5.x and 627,757 running WordPress 4.x. Further back, WordPress 3.x and 2.x together account for approximately 114,000 websites still in active operation.
The U.S.-specific breakdown mirrors this pattern at a national level. Of the 16.6 million outdated American sites identified, 13.2 million remain a full generation behind on WordPress 6.x, spanning the 2022-2026 period. A further 360,000 U.S. sites are still running WordPress 5.x, which dates to 2018. Another 191,000 are on WordPress 4.x, first released in 2014, and roughly 45,000 U.S. sites are running versions dating back to between 2005 and 2010.
Given the size of the American WordPress market, U.S. websites account for more than two in five of all outdated WordPress sites identified anywhere in 20i's worldwide analysis. Only 12.14 percent of U.S. WordPress sites were running version 7.1 at the time of the research, meaning roughly one in eight American installations had moved to the newest release.
Comparing the United States and the United Kingdom
20i's research also examined the United Kingdom as a point of comparison. Almost nine in ten UK WordPress websites, 88.61 percent, were found to be running a version below 7.1. Based on the approximately 1.64 million UK WordPress sites captured in 20i's dataset, that figure translates to around 1.45 million outdated websites in the UK alone.
The UK figure sits close to the global average of 87.62 percent, suggesting the update gap is not concentrated in any single market but rather distributed fairly evenly across major English-speaking regions where WordPress has substantial market penetration. The U.S. figure of 87.86 percent and the UK figure of 88.61 percent differ by less than one percentage point, despite the two markets varying enormously in scale.
Outdated software is not confined to smaller organizations
One of the more counterintuitive findings in 20i's research concerns the relationship between business size and update behavior. Micro-businesses, defined in the study as organizations generating between $100 and $10,000 in annual revenue, recorded the highest rate of outdated WordPress installations globally at 88.42 percent. That figure might be expected given the more limited technical resources typically available to very small organizations.
However, the research found that even enterprise-level organizations, defined as those generating more than $100 million annually, showed an outdated rate of 86.76 percent. With only 1.66 percentage points separating micro-businesses from enterprises, 20i's data indicates that delayed WordPress updates cut across organizational scale rather than tracking neatly with resource availability.
The reasons behind delayed updates likely differ by organization type, even where the outcome looks similar. Smaller organizations may have limited time or technical staff available for routine website maintenance. Larger, more complex enterprise sites, by contrast, may require more extensive compatibility and regression testing before a major update can be safely deployed, given the number of integrated systems, plugins and custom functionality that a large site typically carries. The research identifies the scale of the update gap across business sizes without attributing specific causes to individual organizations' decisions to remain on older versions.
Financial exposure tied to outdated installations
20i's analysis attached a revenue dimension to the update gap by calculating the annual revenue associated with organizations running outdated WordPress software. Using the minimum revenue threshold for each business category multiplied by the number of sites within that category, the research found that organizations running outdated WordPress websites in the dataset represent at least $391 billion in combined annual revenue.
That figure breaks down unevenly across business size. Enterprise organizations account for at least $251.7 billion of the associated revenue, the largest single share. Mid-market businesses account for $93.68 billion, and small and medium-sized businesses account for a further $34.65 billion. The concentration of revenue exposure at the enterprise level reflects a straightforward mathematical reality: while smaller businesses are statistically more likely to be running outdated software, the sheer scale of revenue generated by larger organizations means the financial stakes of any resulting security incident are considerably higher at that end of the market.
Outdated software is not automatically synonymous with vulnerability, and 20i's research does not claim otherwise. But the analysis notes that missed security updates can leave known weaknesses open to exploitation. A successful breach could affect an organization's revenue through several channels, including downtime, lost sales, customer churn, reputational damage and possible regulatory costs. Ecommerce businesses are described as particularly exposed in scenarios where disruption prevents customers from completing purchases.
Vulnerability exploitation as the leading breach vector
20i situated its WordPress-specific findings within a wider cybersecurity context by referencing recent data on how organizations are being breached in general. According to the research, software vulnerabilities have become the leading way that hackers break into organizations, accounting for almost a third, 31 percent, of all breaches.
That statistic traces back to Verizon's 2026 Data Breach Investigations Report, which found that exploitation of vulnerabilities accounted for 31 percent of breaches within its reporting dataset, making it the most common initial access vector identified in that report for the first time.
This context matters for interpreting the WordPress figures because it establishes that the update gap is not an abstract housekeeping concern. Software vulnerabilities, of the kind that WordPress security releases are specifically designed to close, have overtaken other attack methods as the primary route hackers use to gain unauthorized access to systems. A CMS running months or years behind the current release is, by definition, missing whatever fixes have been issued in that interval.
The role of artificial intelligence in shrinking the patch window
Both the press release distributed by 20i's public relations representatives and the more detailed research report published on the company's own site point to a specific concern about how the timeline for patching vulnerabilities is changing. The research references guidance from the UK's National Cyber Security Centre, which has stated that AI-assisted vulnerability research and exploit development is likely to become one of the most significant developments in cyber threats. The National Cyber Security Centre expects artificial intelligence to improve attackers' ability to exploit known vulnerabilities and further reduce the time between a vulnerability being publicly disclosed and being actively exploited in the wild.
This assessment aligns with Cobb's comments regarding the accelerating pace of exploitation. The traditional assumption that organizations have a reasonable window of days or weeks to apply a patch before attackers weaponize a disclosed vulnerability is, according to this framing, becoming less reliable as AI tools lower the barrier to identifying and automating attacks against known weaknesses.
What 20i recommends for website operators
The more detailed version of 20i's research, published on the company's own website and authored by Danny Watkinson, outlines a series of practical steps for website owners seeking to close the gap between their current WordPress version and the latest release. These include applying WordPress security and maintenance releases promptly, keeping plugins and themes updated, removing plugins and themes that are no longer required or actively maintained, and maintaining reliable backups before making significant changes to a live site.
The research also recommends testing major updates against important plugins, themes and any custom functionality before deployment, using a staging environment ahead of higher-risk changes, and monitoring websites after updates are applied to catch any errors or compatibility problems that emerge only once a change goes live.
20i's own commercial offering is positioned within this framework as a way to reduce the burden of routine maintenance. The company states that its WordPress hosting product includes automatic WordPress core updates, daily backups, malware scanning and staging environments. For agencies managing multiple client websites, the research suggests that reseller hosting arrangements can help centralize maintenance responsibilities, while managed hosting providers more broadly can reduce the amount of infrastructure that businesses need to directly oversee in order to keep their sites updated.
Context around WordPress 7.1 and the current release cycle
WordPress 7.1 represents the platform's most recent major version, following the release of WordPress 7.0 earlier in 2026. The 7.0 release itself introduced substantial changes to the platform's architecture, including native artificial intelligence integration through a Connectors API and AI Client, alongside a redesigned administrative dashboard. The subsequent 7.0.x point releases, including 7.0.2, 7.0.3 and 7.0.4, addressed security issues that emerged in the months following that major release, before WordPress 7.1 arrived in August as the newest stable version incorporating those accumulated fixes along with further security work.
This release cadence illustrates a structural challenge that runs through 20i's findings. Even organizations that adopted WordPress 7.0 promptly upon its release would, by the time of 20i's research, have needed to apply at least four subsequent point releases to remain current with all known security fixes. The data suggesting that 63 percent of outdated sites specifically fall within the 6.9 through 7.0.1 range indicates that a substantial portion of the update gap consists of organizations that adopted a recent major version but then fell behind on the smaller, more frequent security patches that followed.
Why this matters for the marketing and advertising community
For professionals working in paid media, search marketing and broader digital advertising, the state of the websites that ultimately receive traffic from campaigns carries direct operational consequences. A landing page built on an outdated and compromised WordPress installation can affect conversion tracking, damage domain reputation with ad platforms, and in more severe cases, result in a site being flagged or blocked by browsers and search engines as unsafe. PPC Land (https://ppc.land), the independent publication covering programmatic advertising and broader ad tech developments, has consistently tracked how infrastructure-level issues, from ad fraud to platform policy changes, intersect with the practical realities facing advertisers, agencies and publishers who depend on functioning digital properties to run campaigns.
The financial exposure figures in 20i's research are particularly relevant to marketing organizations that manage websites on behalf of enterprise clients or that operate ecommerce properties central to revenue generation. An agency responsible for a client's landing pages, or an in-house marketing team managing a company's primary website, sits at the intersection of the technical maintenance burden described in the research and the commercial consequences of a security incident. Downtime or a compromised site during an active campaign period represents both a direct loss of traffic and a potential erosion of the client relationship built on demonstrated performance.
The AI-accelerated threat timeline referenced in the research also has implications for how marketing organizations think about the cadence of their own technical maintenance processes. If the window between a vulnerability's disclosure and its active exploitation continues to compress, the traditional practice of batching WordPress and plugin updates into quarterly or even monthly maintenance cycles may leave a meaningful gap of exposure that campaigns, and the budgets tied to them, could be running through without visibility into the underlying risk.
Summary
Who: Web hosting provider 20i conducted the research, with comments provided by Lloyd Cobb, the company's director. The findings concern WordPress website operators across the United States, the United Kingdom and globally, spanning businesses from micro-enterprises to organizations generating more than $100 million in annual revenue.
What: New analysis found that 87.86 percent of U.S. WordPress websites, representing over 16.59 million sites, are running software below WordPress 7.1, the platform's latest and most secure release. Globally, 87.62 percent of more than 44 million WordPress sites analyzed were found to be outdated, with organizations running these sites collectively associated with at least $391 billion in annual revenue.
When: 20i distributed the press release and published the full research report on September 22 and 23, 2026. The underlying data reflects the period following the release of WordPress 7.1 on August 19, 2026, and follows a sequence of three WordPress security releases issued in less than four weeks during July and August of that year.
Where: The research covers WordPress websites in the United States and United Kingdom specifically, alongside a global dataset of more than 44 million live WordPress installations. 20i is a web hosting company based in Nottingham and Manchester, United Kingdom.
Why: The research arrives amid what 20i describes as a growing threat from hackers exploiting software vulnerabilities, which Verizon's 2026 Data Breach Investigations Report identified as the leading initial access vector for breaches, accounting for 31 percent of incidents. The UK's National Cyber Security Centre has separately warned that AI-assisted vulnerability research is likely to reduce the time between a flaw's disclosure and its exploitation, adding urgency to the update gap the research describes.
Discussion