Skip to content

News

25 September 2026

The legacy problem: why most newsrooms still publish on systems built for another era

The average media company runs its most valuable asset on a stack of plug-ins it did not write and cannot fully control. The costs are measurable – in security, in lost revenue and in the hours a small newsroom spends working around its own tools.

The legacy problem: 11 334 WordPress vulnerabilities in 2025, 91 percent of them in plug-ins

A platform built for websites, stretched into a newsroom

WordPress was designed as a blogging tool in 2003 and grew into the world's most used website system: 40.7 percent of all websites and 58.9 percent of the content management market run on it, according to W3Techs (September 2026). For a media company that is both the good news and the problem. The core is solid, but almost nothing a newsroom needs – translation, SEO, shopping links, revenue reporting, newsletters, paywalls, analytics – is in it. Each capability is added as a plug-in, from a directory of more than 71 000, or bought as a separate service. The result is not a platform but a patchwork, and the patchwork is where the trouble starts.

Security: 11 334 new vulnerabilities in one year

Patchstack's State of WordPress Security 2026 report counted 11 334 new vulnerabilities in the WordPress ecosystem in 2025, a 42 percent increase on the 7 966 found in 2024. Ninety-one percent were in plug-ins; only six were in WordPress itself. Almost half – 46 percent – were made public before a fix existed. Attackers move fast: 20 percent of vulnerabilities were exploited within six hours of disclosure, 45 percent within a day and 70 percent within a week, with a weighted median of five hours. Traditional hosting defences blocked between 12 and 26 percent of the attacks Patchstack tested.

For a small publisher this is not an abstract risk. Every plug-in is a promise to keep updating, and every update is a chance that something else breaks. WordPress.org's own statistics show that while 68.1 percent of sites run the current 7.x series, close to a third still run 6.x or older – often because an update would break a plug-in the business depends on.

Data: fragmented by design

The second cost is quieter. Readership lives in an analytics tool, revenue arrives in monthly reports from affiliate networks, the archive sits in the CMS, the newsletter list in a third service and the audience – the people who come back – belongs to nobody. Decisions get made on habit because the evidence never meets. Few publishers can say what a single article earned, so time and money follow what always worked rather than what works now. The industry's own surveys confirm the appetite for change: 90 percent of executives in WAN-IFRA's World Press Trends Outlook 2025–2026 named data analytics as an investment priority, and 97 percent of the leaders surveyed by the Reuters Institute called back-end automation important.

AI as a bolt-on

The third cost is new. Newsrooms are adopting AI faster than their systems can absorb it: 93 percent of executives call AI and automation a top investment, yet only 30.7 percent describe their adoption as advanced. In practice that means text pasted between a chat window and the CMS – with no rights, no revision history and no record of what an agent actually did. A legacy system has no concept of an AI colleague with a role, a section and a log; it only knows users who can do everything or nothing.

Why the legacy stays

If the costs are so visible, why does the legacy persist? Because it is protected – by the vendor whose revenue depends on it, by the agency that built the theme, by the IT function that controls the keys, and by a reasonable fear in the newsroom that the alternative is a migration project with a date that keeps moving. As long as changing systems means losing the archive, the rankings and six months of everyone's time, the safe decision is to add one more plug-in.

The legacy problem in numbersFigureSource
New WordPress-ecosystem vulnerabilities, 202511 334 (+42 % vs 2024)Patchstack, State of WordPress Security 2026
Share found in plug-ins91 % (six in WordPress core)Patchstack
Vulnerabilities public before a fix46 %Patchstack
Exploited within 24 hours of disclosure45 % (median five hours)Patchstack
Attacks blocked by traditional hosting defences12–26 %Patchstack
Sites on an older WordPress series than the current oneabout 32 % (6.x, 5.x, 4.x)WordPress.org statistics, September 2026
Executives naming AI/automation a top investment93 % (30.7 % consider their adoption advanced)WAN-IFRA

What leaving the legacy actually requires

The way out is not another migration project. It is a system that starts on top of what a publisher already runs, so that readers notice nothing while the newsroom moves; that imports the archive rather than abandoning it; that gives AI colleagues roles, rights and a log rather than a chat window; and that attributes every euro to the article that earned it, so the business can finally see what its own assets are worth. That is the standard VOR was built to – on our own titles first – and it is the only kind of change a small newsroom can actually make: step by step, with control kept where it belongs.

SourcesPatchstack, State of WordPress Security in 2026 (2026), as reported by The Repository and WP Content.W3Techs, market share trends for content management systems (September 2026); WordPress.org version statistics and plugin directory (September 2026).WAN-IFRA, World Press Trends Outlook 2025–2026 (January 2026).Reuters Institute for the Study of Journalism, Journalism, Media and Technology Trends and Predictions 2026 (January 2026).