Plugin vulnerabilities target financial data
Financial services sites are attractive targets because attackers know they handle sensitive prospect and client data, including nonpublic personal information regulated under the Gramm-Leach-Bliley Act. A plugin that went six months without an update isn't a minor inconvenience. It's an open door.