The accessory bought from a different manufacturer - and the most hole-riddled part of your site.
WordPress, the platform your site is built on, handles the basics - pages, images, text. It doesn't accept payments. It doesn't show a map. It doesn't pop up a newsletter window. For all of that, you install a plugin - a small add-on someone else wrote and released for the whole world to use.
Think of it as an accessory bought from another manufacturer. Your phone is made by one company. The case you put on it is from a completely different one - smaller, less known, sometimes a single person making it in their spare time. The case fits fine, looks decent, but nobody has checked it against the phone's own standards.
That's exactly the hole. The big platform has a team that maintains it, patches it, watches it for problems. A plugin often has one author. If they stop updating it, if they sell their account, if they simply make a mistake - the hole stays in your site, not theirs.
That's why most real breaches don't go through the platform itself. They go through a forgotten form plugin - installed a while back, never updated since, because it sits behind the logic of 'it works, why touch it'.
The detail talks
Every time I check a client's site, I look at the plugin list first, not the platform itself. That's where the history is - what's installed, when it was last updated, who's even still maintaining it. I usually find something forgotten, bought for one specific campaign years ago and left to gather dust.
I'm not writing this to scare you off plugins - without them your site won't do much of anything interesting. I'm writing it because the fix is boringly simple: a list, a review, deleting what's unneeded. Nobody does it, because nobody sees it as work.