To a degree, this is by intention of those doing the attacking. They would rather have the site up and running, while the spam, code injection and backdoor can sit there earning them money. It's not until the spam causes damage (or is visible enough) that someone calls someone who is in charge, who in turn might hire a web developer, who in turn calls the hosting company in order to figure out that a 5 year old WordPress site that someone else put together has not been updated. Then it can take even longer until the new web developers has negotiated a price to fix the situation.
Members of the public would have to look pretty hard to find the majority of these issues: they generally don't view source code and and even if they searched kidwelly.gov.uk for viagra the spam pages aren't indexed.
http://shkspr.mobi/blog/2014/03/2000-nhs-security-vulnerabil...
The problem is that there isn't a formal plan for decommissioning the Web site - perhaps turning it into static HTML with an 'archived' banner at the top.