In 2025, Patchstack recorded 11,334 new vulnerabilities in the WordPress world, 42% more than in 2024. The number makes headlines every year. It is frightening, and almost useless as it stands: nearly two thirds of those flaws pose practically no threat to an ordinary site.
What matters hides behind that total. Where the flaws are, which ones are actually exploited, how long attackers take to use them, and how many have no fix on the day they go public. Those answers change how you maintain a site.
This guide reads the latest reports from Patchstack, Wordfence and WPScan the way a site owner should: looking for what calls for action. It keeps a handful of figures that carry a line of reasoning, explains why the sources do not all say the same thing, and ends with a prioritized list of actions.
Where the numbers come from
Three vendors, three ways of counting
Three security companies specialized in WordPress publish most of the data. Patchstack releases an annual report, “State of WordPress Security”, whose February 2026 edition covers 2025. Wordfence published an annual report up to its 2024 edition, then moved to quarterly reports. WPScan, owned by Automattic, published its last annual report on 2023 data.
Their totals do not match, and that is not a mistake. Wordfence counts one vulnerability per CVE identifier; others may count one entry per affected piece of software. For 2024, Patchstack reported 7,966 flaws, Wordfence 8,223. Keep one simple rule: never use a figure without naming its source and the year of the data.
Bounties and AI inflate the volume
Since 2021, these vendors have been CVE Numbering Authorities (WPScan since January, Wordfence and Patchstack since June), and they pay researchers who report flaws to them. More bounties, more researchers, more published flaws: the volume reflects research effort as much as code quality.
AI is accelerating that trend. According to Wordfence, the share of reports to its bug bounty program where researchers say they use AI went from 16% in late November 2025 to about 66% in April 2026. Patchstack tightened its bounty program in June 2026, after receiving more than twenty duplicate reports for some flaws. A falling total therefore does not necessarily mean the code is getting better.
Attack figures, another measure
Alongside published flaws, vendors measure the attacks they see. In the second quarter of 2026, Wordfence reported more than ten billion malicious requests blocked by its firewall, more than eighteen billion brute-force login attempts, and more than half a million infected sites detected. These figures come from the sites it protects: they show the intensity of the background noise, not the probability that a given site is compromised.
Plugins, themes, core: where the flaws are
Plugins first
This is the most stable figure across all the reports. According to Patchstack, 91% of the new vulnerabilities of 2025 affected plugins and 9% themes; WordPress core had only six, all low priority. Wordfence found a 96% share for plugins in 2024 and five flaws in core.
Themes are fewer but more dangerous in proportion: in Patchstack’s 2025 data, more than half of theme flaws were rated high priority, against about one in seven for plugins, by our calculation from its charts.
Most flaws do not threaten an ordinary site
Of the 11,334 flaws of 2025, Patchstack rates about 7,200 as low priority, and 1,966 as high priority. Wordfence said the same of 2024: more than 68% of published flaws were low risk for most site owners. A flaw that requires an administrator account to exploit, for example, changes little: an administrator already has every right.
But the dangerous slice is growing fast: highly exploitable flaws more than doubled between 2024 and 2025, from 923 to 1,966 according to Patchstack. That slice is where all the maintenance effort belongs.
Core, an exception in 2026
For years, WordPress core was the safest part of the whole. 2026 changed that. Between March and September, WordPress’s official announcements list 37 distinct security fixes, by our count. And for the first time, three core flaws entered the US agency CISA’s catalog of exploited vulnerabilities.
Core remains well maintained: fixes arrived quickly, some through forced updates. But the idea that it is never the problem no longer holds. Our guide to WordPress security hardening covers the July 2026 chain of flaws.
How core is protected
Core benefits from an organization few plugins can afford. A security team of more than fifty experts handles reports, and a bug bounty program on HackerOne, opened in April 2017, pays researchers; bounties are doubled for a flaw reported before it reaches users. Fixes are backported as a courtesy to older branches, currently as far as version 4.7, branches 4.1 to 4.6 having been dropped in July 2025.
Only the latest version is officially supported. Automatic minor updates, on by default, deliver these fixes without intervention: that is the main reason never to turn them off.
Which flaws, and which ones matter
Most reported is not most exploited
The most frequently published flaws are cross-site scripting, or XSS: 46% of 2024 flaws according to Wordfence, ahead of missing authorization checks, at 13%, and cross-site request forgery, or CSRF, at 11%. In 2026, in Wordfence’s quarterly reports, missing authorization even overtook XSS in the first quarter.
But real attacks target something else. In Patchstack’s 2025 exploitation data, measured on the attacks its rules blocked, broken access control accounts for 57% and privilege escalation for 20%. These attacks look like normal logged-in user traffic, with no obvious injection pattern, which makes them hard to filter. Wordfence noted that arbitrary file upload accounted for 38% of high-risk flaws in 2024.
The real question: do you need to be logged in?
To judge a flaw, look first at the level of access it requires, before its score. A flaw exploitable by an anonymous visitor concerns every site using the plugin. A flaw requiring a subscriber account only concerns sites that allow registration. A flaw requiring an administrator account concerns almost no one.
The figures vary between reports, and it helps to know why. Patchstack stated that 43% of 2024 flaws required no authentication, counting request forgery, which tricks a logged-in user. Wordfence separated purely anonymous flaws, 19%, from those that also require a user action, 23%. Together, 42%: both sources say the same thing.
Our guide to WordPress user roles explains how to limit what a low-level account can reach.

The real case: Elementor Pro, attacked on disclosure day
Elementor Pro’s CVE-2026-32475 flaw, in the summer of 2026, illustrates almost every figure in the reports on its own: a paid plugin, an arbitrary file upload, exploitation the same day, two different scores for the same flaw, and an official catalog that stays silent. It is documented by Patchstack, by Wordfence and by the CVE record.
A flaw in a form field
Elementor Pro is the paid extension of the Elementor page builder, sold outside the official directory. Wordfence estimates it is installed on more than six million sites. Its forms module offers a file upload field. The file extension check stopped too early: if the first submitted entry was empty, the validation loop exited instead of moving on to the next one, and the next file escaped the check.
That file, a PHP script for example, was then saved in a public folder. An anonymous visitor could therefore run code on the server. Patchstack summed it up vividly: “the distance between a working defense and an unauthenticated RCE is one keyword”. One condition applied: the site had to publish an Elementor Pro form with an optional file upload field, a common setup since the field is optional by default, according to Patchstack.
Two researchers, two authorities, one identifier
On July 16, 2026, a researcher, Tin Pham (TF1T), reported the flaw to Patchstack, which confirmed it, contacted the vendor and assigned the identifier the same day. On July 24, a second researcher, Austin Ginder, reported it independently to Wordfence, which validated it and passed it to Elementor on the 27th. On August 2, Elementor told Wordfence that another researcher had already reported the same flaw; Wordfence then withdrew its own identifier in favor of Patchstack’s.
On August 3, Patchstack checked the fix the vendor had prepared. The fix was released on August 19, thirty-four days after the first report.
August 19: the fix and the attacks
On disclosure day, Patchstack rated the flaw 9.0 out of 10, Wordfence 9.8. Same flaw, two scores: the two vendors did not assess the complexity of the attack, or the scope of its impact, the same way. Two hours later, the assessment CISA added to the record stated that no exploitation was known.
Wordfence saw the opposite. In its words, “attackers started targeting websites the same day the vulnerability was disclosed”, with a peak of attacks from August 19 to 23. By September 2, its firewall had blocked more than 190,000 exploit attempts. The observed payload was a PHP script that tried several command execution functions in turn.
In early October 2026, the flaw still does not appear in CISA’s catalog of exploited vulnerabilities. It does, however, carry the known-exploited label in Patchstack’s database.
What owners had to check
Updating closed the door, but did not undo a successful attack. Both vendors recommended looking for any PHP file in the /wp-content/uploads/elementor/forms/ folder, and Wordfence warned that the absence of traces in the logs did not guarantee the site was clean. Elementor’s changelog does not name this flaw: the August 19 entry only mentions improved security enforcement in template handling, and its version numbers do not match the one cited by Patchstack and Wordfence. A reminder that vendors do not always name their security fixes clearly.
What the case illustrates
Paid plugins are less audited: Patchstack observed three times more exploited flaws in paid components than in free ones in 2025. Attackers move fast: about half of high-impact flaws are exploited within twenty-four hours. Scores vary depending on who calculates them. And CISA’s official catalog sees almost nothing of what happens in WordPress plugins.
Time to fix, time to exploit
No fix on disclosure day
According to Patchstack, 46% of 2025 flaws had not received a fix from their developer when they were published, against 33% in 2024. Read it carefully: this does not mean these flaws will never be fixed, but that they went public before a fix existed. An update notification does not protect you against those flaws, since there is nothing to update.
Attacks within hours
Patchstack estimates that about half of the high-impact flaws of 2025 were exploited within twenty-four hours, with a weighted median of five hours before the first attack. A weekly update round is too slow for these flaws. They call for automatic updates, a web application firewall, or removing the plugin.
Old flaws remain the favorite targets
The number one target of the second quarter of 2026, according to Wordfence, is a LiteSpeed Cache flaw fixed in August 2024, with nearly 50 million blocked requests. Fixed within twelve days at the time, it is still targeted two years later, because unpatched copies are still running. Patchstack makes the same observation: of the ten most attacked flaws of 2025, only four had been published in 2025.
Forgotten sites, old staging copies or campaign sites, are the most exposed. Our WordPress maintenance checklist organizes how to keep track of them.
Abandoned and closed plugins
In 2024, according to Patchstack, 1,614 plugins and themes were removed from the official directory for unpatched flaws. The problem is that WordPress shows nothing: a closed plugin appears in the admin as an up-to-date plugin. Wordfence said so in its 2024 report: removing unused and abandoned plugins could be critically important.
The command line, however, can tell. The wporg_status field shows closed for a plugin removed from the directory, as our selection of essential WP-CLI commands shows.
wp plugin list --fields=name,status,version,update_version,auto_update,wporg_status
CVE, authorities and scores: reading a vulnerability record
Who assigns identifiers
Wordfence, Patchstack and WPScan are all three CVE Numbering Authorities, under MITRE’s supervision. According to the US NVD database, together they published more than 11,000 identifiers in 2025, nearly a quarter of all CVE identifiers published worldwide that year, by our calculation. WordPress therefore weighs heavily in the global vulnerability tracking system.
Why scores differ
The CVSS score, from 0 to 10, measures a flaw’s theoretical severity, not its risk to your site. Two authorities can score the same flaw differently, as with Elementor Pro. A core flaw scored 5.9 was nonetheless exploited in 2026.
Both vendors acknowledge it themselves: Patchstack created its own priority score because CVSS rarely rates a WordPress flaw as low severity, and Wordfence considers CVSS poorly suited to measuring real risk.
Since April 2026, the US institute NIST no longer routinely adds its own score to NVD records when the assigning authority has already provided one. The score you read is therefore, most of the time, that of the security vendor that published the flaw.
The catalog that sees almost nothing
CISA’s catalog of exploited vulnerabilities is the reference for US agencies. In early October 2026, it listed only three WordPress plugin flaws, all added in 2021, and three core flaws added in 2026. The “exploited” labels of Patchstack or Wordfence are based on their own observations. Do not confuse the two.
The day the CVE system wobbled
On April 15, 2025, MITRE warned the CVE program’s board that the US government did not intend to renew its management contract. The next day, CISA exercised an eleven-month extension option, and the service was not interrupted. The program kept running under its stewardship. For WordPress, whose vendors publish a considerable share of identifiers, an interruption would have directly disrupted vulnerability tracking.
What these numbers mean for your site
The reports paint a consistent picture. Almost all flaws are in plugins and themes, not in core. Most do not threaten an ordinary site, but the dangerous slice is growing, it is often published without a fix, and it is exploited within hours. Paid plugins, abandoned plugins and old forgotten sites concentrate the risk.
Also keep in mind that each vendor sells protection: Patchstack virtual patching, Wordfence a firewall, WPScan and Jetpack Automattic’s tools. Their figures are serious, but their conclusions often point toward their product. Our comparison of WordPress security plugins helps you choose without being driven by fear.
A prioritized action list
- Know exactly what is running, paid plugins included. List every plugin and theme, active or not, with its version and its status in the directory.
- Delete what you do not use, replace what is abandoned. A deactivated plugin keeps its files on the server.
- Get alerts that cover flaws without a fix. Nearly half of 2025 flaws had none at disclosure: the free feeds from Wordfence, Patchstack or WPScan flag them.
- Fix the dangerous slice within hours. Turn on automatic updates for plugins you trust, keep core’s on, and keep your paid licenses active so you receive fixes.
- When no fix exists, remove or shield. Deactivate the plugin or use a virtual patch; the free version of Wordfence gets its new rules thirty days later.
- Reduce what anonymous visitors and low-level accounts can reach. Close registration if it is not used, watch forms with file upload, block PHP execution in the media folder.
- Triage by exploitability, not by score. Ask three questions: do you need to be logged in, with which role, is the flaw exploited?
- Assume old flaws are still hunted. Check old sites and forgotten staging copies first.
- Watch for signs of intrusion and keep a way out. Unknown administrators, PHP files in the media folder, unexpected must-use plugins; and off-server backups, chosen among the WordPress backup plugins.
Summary table
| Report | Data | What it shows | Takeaway |
|---|---|---|---|
| Patchstack 2026 | 2025 | 11,334 flaws, 91% in plugins, 46% with no fix at disclosure | About half of high-impact flaws exploited within 24 hours |
| Patchstack 2025 | 2024 | 7,966 flaws, 1,614 plugins and themes removed | Closed plugins look up to date |
| Wordfence 2024 | 2024 | 8,223 flaws, XSS first, more than 68% low risk | Access level matters more than score |
| Wordfence Q2 2026 | April to June 2026 | A 2024 flaw is still the number one target | Old flaws never die |
| CISA catalog | September 2026 | Three WordPress plugin flaws, three core flaws | Absent does not mean unexploited |
| WordPress announcements | March to September 2026 | 37 core security fixes, by our count | Keep core automatic updates on |
Frequently asked questions
Is WordPress core safe?
Yes, and it is well maintained, but 2026 showed it is not immune: three of its flaws were exploited. Fixes arrive quickly and often automatically. Keep minor updates automatic.
Should I worry about every vulnerability alert?
No. First check whether the flaw requires an account, with which role, and whether it is exploited. A flaw requiring an administrator account changes almost nothing; an anonymous flaw in a plugin you use calls for action the same day.
Are paid plugins safer than free ones?
Not necessarily. According to Patchstack, they are less audited and showed three times more exploited flaws than free ones in 2025. An active license remains essential to receive fixes.
Why do Patchstack and Wordfence give different totals?
Because they do not count the same way, nor from the same reports. Compare trends within a single source, never totals from one source to another.
Does a firewall replace updates?
No. It protects while you wait for a fix, or against generic attacks. But the only lasting protection remains the update, or removing the vulnerable plugin.
What does “closed” mean in the WordPress directory?
That the plugin was removed from the official directory, often for an unpatched flaw. It no longer receives updates through that channel, and WordPress does not warn you: only a command-line check, a security tool or the plugin’s page on WordPress.org flags it.
Conclusion
WordPress vulnerability figures are frightening because people read them in bulk. Read with method, they say something precise: risk is concentrated in a small slice of serious flaws, mostly in plugins, often published without a fix and exploited within hours, and in old flaws never fixed on forgotten sites.
The Elementor Pro story demonstrates it: a paid plugin installed on millions of sites, attacked the same day, scored differently by two vendors, ignored by the official catalog. Know what is running, delete what you do not use, fix quickly and triage by exploitability: that is what these numbers ask of you.
Sources
- Patchstack (February 2026). State of WordPress Security in 2026
- Patchstack (March 2025). State of WordPress Security in 2025
- Wordfence (April 8, 2025). 2024 Annual WordPress Security Report
- Wordfence (September 29, 2026). Quarterly WordPress Threat Intelligence Report, Q2 2026
- Wordfence (June 4, 2026). Quarterly WordPress Threat Intelligence Report, Q1 2026
- Wordfence (April 10, 2026). The Increasing Role of AI in Vulnerability Research
- Patchstack (May 29, 2026). The future of the Patchstack bug bounty program
- Wordfence (August 20, 2026). Critical Arbitrary File Upload Vulnerability Patched in Elementor Pro
- Wordfence (September 2, 2026). Attackers Actively Exploiting Critical Vulnerability in Elementor Pro Plugin
- Patchstack (August 19, 2026). Critical Unauthenticated File Upload to RCE in Elementor Pro Plugin
- CVE.org. CVE-2026-32475
- Elementor. Elementor Pro changelog
- CISA. Known Exploited Vulnerabilities Catalog
- WordPress.org. Security
- HackerOne. WordPress bug bounty program
- WordPress.org News (July 17, 2026). WordPress 7.0.2 Release
- WordPress.org News (August 6, 2026). WordPress 7.0.3 Release
- WordPress.org News (September 22, 2026). WordPress 7.1.2 Release
- CVE Program. Partner: Wordfence
- CVE Program. Partner: Patchstack
- CVE Program. Metrics
- NIST (April 15, 2026). NIST Updates NVD Operations to Address Record CVE Growth
- BleepingComputer, Sergiu Gatlan (April 16, 2025). CISA extends funding to ensure no lapse in critical CVE services
- CVE Foundation (April 16, 2025). CVE Foundation Launched to Secure the Future of the CVE Program
- Patchstack (October 18, 2024). Security implications of WordPress repository access restrictions and plugin closures
- Patchstack (August 21, 2024). Critical Privilege Escalation in LiteSpeed Cache Plugin
- WPScan. 2023 Website Threat Report
- WP-CLI. wp plugin list
- WordPress.org News (March 10, 2026). WordPress 6.9.2 Release
- WordPress.org News (August 12, 2026). WordPress 7.0.4 Release
- WordPress.org News (September 17, 2026). WordPress 7.1.1 Maintenance and Security Release
- WordPress.org News (June 19, 2025). Dropping security updates for WordPress versions 4.1 through 4.6
- CVE.org. CVE-2026-60137
- Patchstack (August 19, 2026). Arbitrary File Upload in WordPress Elementor Pro Plugin
- CVE Program. Partner: WPScan
- NIST. NVD Vulnerability API
- WPScan (January 12, 2021). WPScan authorized as a CVE Numbering Authority by the CVE Program
- Wordfence (June 10, 2021). Wordfence is now a CVE Numbering Authority (CNA)
- Patchstack (June 16, 2021). Patchstack Is Now A CVE Numbering Authority
- WP-CLI (GitHub). extension-command, Plugin_Command.php
LaFactory designs, builds and maintains WordPress and WooCommerce sites, and develops its own plugins. Talk to us about your WordPress project.
