Your Plugins and Core Are Behind on Updates
Out-of-date WordPress plugins are the most common entry point for site compromises. Public vulnerability databases publish WordPress plugin vulnerabilities regularly, and automated scanning tools probe sites for known unpatched versions continuously. If your plugin list has not been reviewed and updated on a scheduled basis, your site is on those lists. Updates are not optional maintenance. They are the primary technical defence against known exploits.