The WordPress Update Gap: 88% of WordPress Sites Are Behind the Latest Release

Keeping WordPress up to date has always been an important part of website maintenance, but the need to apply security fixes quickly is becoming harder to ignore. 

WordPress issued three security releases in less than four weeks during July and August, 2026. WordPress 7.0.2 addressed one critical and one high severity security issue, followed by several further security fixes in 7.0.3 and another in 7.0.4.

WordPress recommended that users update immediately following each release. 

At the same time, the window for applying security fixes could get shorter. The UK’s National Cyber Security Centre says AI assisted vulnerability research and exploit development is likely to become one of the most significant developments in cyber threats.  

It expects AI to improve attackers’ ability to exploit known vulnerabilities and further reduce the time between a vulnerability being disclosed and exploited. 

WordPress 7.1, released on 19 August 2026, is now the latest version.

➡️ To understand how closely the web is keeping pace, we analysed more than 44 million live WordPress websites worldwide, looking at the versions they’re running and how this varies across the US, UK and businesses of different sizes. 

 Our research found that almost nine in 10 WordPress websites are running a version below WordPress 7.1. 

Key findings 

  • 87.62% of WordPress sites analysed globally are running a version below WordPress 7.1, representing more than 38.99 million sites in our research. 
  • WordPress 6.x is still used by 68.11% of sites, making it the most common generation currently active. 
  • 87.86% of US WordPress sites are running a version below WordPress 7.1, compared with 88.61% in the UK. 
  • Outdated WordPress spans businesses of all sizes, from 88.42% of micro-business sites to 86.76% of enterprise sites. 
  • Sites running outdated WordPress versions in our business dataset are associated with at least $391 billion in annual revenue, based on the minimum revenue threshold for each business category. 

How many WordPress websites are running outdated software? 

Our research found that almost nine in 10 (87.62%) WordPress websites globally are running on a version below WordPress 7.1. 

That represents more than 38.99 million websites in our research. Fewer than one in eight sites, 12.38%, were running WordPress 7.1 at the time of our analysis. 

The scale of the update gap is particularly significant as software vulnerabilities play a growing role in cyberattacks. 

Verizon’s 2026 Data Breach Investigations Report found that exploitation of vulnerabilities accounted for 31% of breaches in its reporting dataset, making it the most common initial access vector for the first time. 

WordPress releases updates throughout the year to address security issues, fix bugs and improve how sites run.

When security releases are missed, websites can remain exposed to vulnerabilities that have already been fixed in newer versions. 

Running an older WordPress release does not automatically mean a website is vulnerable, but as the time available to patch known weaknesses gets shorter, keeping WordPress core, plugins and themes current becomes increasingly important. 

Which WordPress versions are websites still using? 

WordPress 6.x is by far the most common generation in our research, accounting for 68.11% of all WordPress sites analysed, or more than 30.3 million websites. 

The WordPress 6.x generation began with WordPress 6.0 in May 2022, but significant numbers of websites are running even older releases. 

Around 1.12 million sites are still using WordPress 5.x and 627,757 are on 4.x, while WordPress 3.x and 2.x together account for around 114,000 websites. 

The figures also show why keeping up with individual security releases matters, rather than focusing only on major WordPress generations. 

WordPress 7.0.2, released in July 2026, addressed one critical and one high severity security issue. Due to their severity, WordPress enabled forced automatic updates for sites that are running affected versions. 

In our dataset, approximately 24.79 million outdated websites, around 63% of the outdated group, were running WordPress 6.9 through 6.9.4 or WordPress 7.0 through 7.0.1. 

These versions fall within the ranges affected by the vulnerabilities subsequently addressed by security releases, showing why keeping up with individual maintenance and security updates is just as important as moving between major WordPress generations. 

Subscribe for the latest 20i news

Get the latest product launches, new features alerts, platform upgrades and exclusive content, all delivered instantly to your inbox.

How outdated are WordPress websites in the US? 

The US closely reflects the global picture, with 87.86% of WordPress websites analysed running a version below WordPress 7.1, compared with 87.62% globally. 

Of the 18.89 million US WordPress sites in our research, around 16.6 million were running an older version. 

Given the size of the US WordPress market, American sites account for more than two in five of all outdated websites identified globally. 

Only 12.14% were running WordPress 7.1, meaning roughly one in eight US sites had moved to the latest release. 

For the millions of US sites running outdated software, there can be practical reasons to delay major WordPress updates. 

If a website relies on plugins, payment systems, themes or custom functionality, taking time to test these against a new release can help avoid compatibility problems. 

The issue comes when a short testing period becomes a long term maintenance backlog, particularly if security updates are missed at the same time. 

How outdated are WordPress websites in the UK? 

Almost nine in 10 (88.61%) UK WordPress websites analysed are running a version below WordPress 7.1. 

Based on the approximately 1.64 million UK WordPress sites in our dataset, that represents around 1.45 million websites. 

This is broadly in line with the global average of 87.62%, showing how widespread outdated WordPress software is across different markets. 

The figures come as website security remains firmly on the agenda for UK businesses. 

The UK Government’s Cyber Security Breaches Survey 2025/2026 found that 43% of businesses experienced a cyber security breach or attack in the previous 12 months, rising to 65% of medium businesses and 69% of large businesses. 

Keeping WordPress up to date cannot prevent every type of cyberattack, but applying security fixes promptly helps close known vulnerabilities for which patches are already available. 

Which businesses are most likely to have outdated WordPress websites? 

Globally, micro-businesses have the highest proportion of outdated WordPress sites in our research at 88.42%. 

However, even among enterprise sites associated with organisations generating more than $100 million annually, the figure stands at 86.76%. 

With just 1.66 percentage points separating micro-businesses and enterprises, outdated WordPress software is clearly not just a resourcing issue limited to smaller organisations. It is a challenge across the market. 

The reasons for delaying an update are likely to look different depending on the business. 

Small or medium-sized organisation may have limited time or technical resources for routine website maintenance, while a complex enterprise site may require more extensive compatibility and regression testing before a major update is deployed. 

Our data identifies the scale of the update gap rather than the reasons individual organisations have remained on a particular WordPress version. 

What is the business impact of outdated WordPress websites? 

Organisations running outdated WordPress websites in our dataset represent at least $391 billion in annual revenue, highlighting the scale of business activity that could be affected when websites fall behind on updates, from security risks to performance and maintenance issues. 

That impact spans businesses of all sizes. Enterprise organisations account for at least $251.7 billion of the associated revenue, while mid-market businesses account for $93.68 billion and SMBs $34.65 billion. 

While smaller businesses are more likely to be running outdated WordPress versions, the greater revenues of larger organisations mean the financial stakes can be particularly high at enterprise level. 

Outdated software isn’t automatically vulnerable, but missed security updates can leave known weaknesses open to attack.  

A breach could affect revenue through downtime and lost sales, as well as customer churn, reputational damage and possible regulatory costs – with ecommerce businesses particularly exposed when disruption prevents customers from buying. 

What can website owners do to stay up to date? 

WordPress 7.1 is the latest and most secure release available, making it the version website owners should be working towards.  

While uptake’s still growing following its recent launch, the major concern is that up to two in three (63%) sites are running flawed versions 6.9 though 6.9.4 and 7.0 to 7.0.1, which have known vulnerabilities that hackers are actively exploiting, putting over 32.9 million sites at risk. 

Website owners should: 

  • Apply WordPress security and maintenance releases promptly 
  • Keep plugins and themes up to date 
  • Remove plugins and themes that are no longer required or maintained 
  • Maintain reliable backups before significant changes 
  • Test major updates against important plugins, themes and custom functionality 
  • Use a staging environment before deploying higher risk changes 
  • Monitor websites after updates for errors or compatibility problems 

Hosting can also reduce the amount of routine maintenance required. Our WordPress hosting includes automatic WordPress core updates, daily backups, malware scanning and staging.  

For agencies managing multiple client websites, reseller hosting can help centralise that maintenance, while choosing a managed hosting provider can reduce the amount of infrastructure businesses need to manage updates themselves. 

Methodology 

We used BuiltWith to analyse the CMS version of live WordPress sites globally, revealing how many of those sites are running outdated software. Versions below WordPress 7.1 were classified as outdated for this analysis. 

Business-size analysis used available annual revenue data, grouping businesses into micro-business ($100-$10K), small business ($10K-$1M), SMB ($1M-$10M), mid-market ($10M-$100M) and enterprise (>$100M) categories. Associated at-risk revenue from outdated websites was calculated using the minimum annual revenue threshold for each business category multiplied by the number of sites within the category. 



Managed WordPress Hosting
Previous Article

PayFast Now Available as a HostShop Payment Gateway 

Write a Comment

Leave a Comment

Your email address will not be published. Required fields are marked *