WordPress Vulnerabilities by the Numbers: What the Latest Reports Show

by Francis Rozange | Oct 2, 2026 | WordPress

In 2025, Patchstack recorded 11,334 new vulnerabilities in the WordPress world, 42% more than in 2024. The number makes headlines every year. It is frightening, and almost useless as it stands: nearly two thirds of those flaws pose practically no threat to an ordinary site.

What matters hides behind that total. Where the flaws are, which ones are actually exploited, how long attackers take to use them, and how many have no fix on the day they go public. Those answers change how you maintain a site.

This guide reads the latest reports from Patchstack, Wordfence and WPScan the way a site owner should: looking for what calls for action. It keeps a handful of figures that carry a line of reasoning, explains why the sources do not all say the same thing, and ends with a prioritized list of actions.

Where the numbers come from

Three vendors, three ways of counting

Three security companies specialized in WordPress publish most of the data. Patchstack releases an annual report, “State of WordPress Security”, whose February 2026 edition covers 2025. Wordfence published an annual report up to its 2024 edition, then moved to quarterly reports. WPScan, owned by Automattic, published its last annual report on 2023 data.

Their totals do not match, and that is not a mistake. Wordfence counts one vulnerability per CVE identifier; others may count one entry per affected piece of software. For 2024, Patchstack reported 7,966 flaws, Wordfence 8,223. Keep one simple rule: never use a figure without naming its source and the year of the data.

Bounties and AI inflate the volume

Since 2021, these vendors have been CVE Numbering Authorities (WPScan since January, Wordfence and Patchstack since June), and they pay researchers who report flaws to them. More bounties, more researchers, more published flaws: the volume reflects research effort as much as code quality.

AI is accelerating that trend. According to Wordfence, the share of reports to its bug bounty program where researchers say they use AI went from 16% in late November 2025 to about 66% in April 2026. Patchstack tightened its bounty program in June 2026, after receiving more than twenty duplicate reports for some flaws. A falling total therefore does not necessarily mean the code is getting better.

Attack figures, another measure

Alongside published flaws, vendors measure the attacks they see. In the second quarter of 2026, Wordfence reported more than ten billion malicious requests blocked by its firewall, more than eighteen billion brute-force login attempts, and more than half a million infected sites detected. These figures come from the sites it protects: they show the intensity of the background noise, not the probability that a given site is compromised.

Plugins, themes, core: where the flaws are

Plugins first

This is the most stable figure across all the reports. According to Patchstack, 91% of the new vulnerabilities of 2025 affected plugins and 9% themes; WordPress core had only six, all low priority. Wordfence found a 96% share for plugins in 2024 and five flaws in core.

Themes are fewer but more dangerous in proportion: in Patchstack’s 2025 data, more than half of theme flaws were rated high priority, against about one in seven for plugins, by our calculation from its charts.

Most flaws do not threaten an ordinary site

Of the 11,334 flaws of 2025, Patchstack rates about 7,200 as low priority, and 1,966 as high priority. Wordfence said the same of 2024: more than 68% of published flaws were low risk for most site owners. A flaw that requires an administrator account to exploit, for example, changes little: an administrator already has every right.

But the dangerous slice is growing fast: highly exploitable flaws more than doubled between 2024 and 2025, from 923 to 1,966 according to Patchstack. That slice is where all the maintenance effort belongs.

Core, an exception in 2026

For years, WordPress core was the safest part of the whole. 2026 changed that. Between March and September, WordPress’s official announcements list 37 distinct security fixes, by our count. And for the first time, three core flaws entered the US agency CISA’s catalog of exploited vulnerabilities.

Core remains well maintained: fixes arrived quickly, some through forced updates. But the idea that it is never the problem no longer holds. Our guide to WordPress security hardening covers the July 2026 chain of flaws.

How core is protected

Core benefits from an organization few plugins can afford. A security team of more than fifty experts handles reports, and a bug bounty program on HackerOne, opened in April 2017, pays researchers; bounties are doubled for a flaw reported before it reaches users. Fixes are backported as a courtesy to older branches, currently as far as version 4.7, branches 4.1 to 4.6 having been dropped in July 2025.

Only the latest version is officially supported. Automatic minor updates, on by default, deliver these fixes without intervention: that is the main reason never to turn them off.

Which flaws, and which ones matter

Most reported is not most exploited

The most frequently published flaws are cross-site scripting, or XSS: 46% of 2024 flaws according to Wordfence, ahead of missing authorization checks, at 13%, and cross-site request forgery, or CSRF, at 11%. In 2026, in Wordfence’s quarterly reports, missing authorization even overtook XSS in the first quarter.

But real attacks target something else. In Patchstack’s 2025 exploitation data, measured on the attacks its rules blocked, broken access control accounts for 57% and privilege escalation for 20%. These attacks look like normal logged-in user traffic, with no obvious injection pattern, which makes them hard to filter. Wordfence noted that arbitrary file upload accounted for 38% of high-risk flaws in 2024.

The real question: do you need to be logged in?

To judge a flaw, look first at the level of access it requires, before its score. A flaw exploitable by an anonymous visitor concerns every site using the plugin. A flaw requiring a subscriber account only concerns sites that allow registration. A flaw requiring an administrator account concerns almost no one.

The figures vary between reports, and it helps to know why. Patchstack stated that 43% of 2024 flaws required no authentication, counting request forgery, which tricks a logged-in user. Wordfence separated purely anonymous flaws, 19%, from those that also require a user action, 23%. Together, 42%: both sources say the same thing.

Our guide to WordPress user roles explains how to limit what a low-level account can reach.

A glass mesh filter with a single gap letting a thin beam through

The real case: Elementor Pro, attacked on disclosure day

Elementor Pro’s CVE-2026-32475 flaw, in the summer of 2026, illustrates almost every figure in the reports on its own: a paid plugin, an arbitrary file upload, exploitation the same day, two different scores for the same flaw, and an official catalog that stays silent. It is documented by Patchstack, by Wordfence and by the CVE record.

A flaw in a form field

Elementor Pro is the paid extension of the Elementor page builder, sold outside the official directory. Wordfence estimates it is installed on more than six million sites. Its forms module offers a file upload field. The file extension check stopped too early: if the first submitted entry was empty, the validation loop exited instead of moving on to the next one, and the next file escaped the check.

That file, a PHP script for example, was then saved in a public folder. An anonymous visitor could therefore run code on the server. Patchstack summed it up vividly: “the distance between a working defense and an unauthenticated RCE is one keyword”. One condition applied: the site had to publish an Elementor Pro form with an optional file upload field, a common setup since the field is optional by default, according to Patchstack.

Two researchers, two authorities, one identifier

On July 16, 2026, a researcher, Tin Pham (TF1T), reported the flaw to Patchstack, which confirmed it, contacted the vendor and assigned the identifier the same day. On July 24, a second researcher, Austin Ginder, reported it independently to Wordfence, which validated it and passed it to Elementor on the 27th. On August 2, Elementor told Wordfence that another researcher had already reported the same flaw; Wordfence then withdrew its own identifier in favor of Patchstack’s.

On August 3, Patchstack checked the fix the vendor had prepared. The fix was released on August 19, thirty-four days after the first report.

August 19: the fix and the attacks

On disclosure day, Patchstack rated the flaw 9.0 out of 10, Wordfence 9.8. Same flaw, two scores: the two vendors did not assess the complexity of the attack, or the scope of its impact, the same way. Two hours later, the assessment CISA added to the record stated that no exploitation was known.

Wordfence saw the opposite. In its words, “attackers started targeting websites the same day the vulnerability was disclosed”, with a peak of attacks from August 19 to 23. By September 2, its firewall had blocked more than 190,000 exploit attempts. The observed payload was a PHP script that tried several command execution functions in turn.

In early October 2026, the flaw still does not appear in CISA’s catalog of exploited vulnerabilities. It does, however, carry the known-exploited label in Patchstack’s database.

What owners had to check

Updating closed the door, but did not undo a successful attack. Both vendors recommended looking for any PHP file in the /wp-content/uploads/elementor/forms/ folder, and Wordfence warned that the absence of traces in the logs did not guarantee the site was clean. Elementor’s changelog does not name this flaw: the August 19 entry only mentions improved security enforcement in template handling, and its version numbers do not match the one cited by Patchstack and Wordfence. A reminder that vendors do not always name their security fixes clearly.

What the case illustrates

Paid plugins are less audited: Patchstack observed three times more exploited flaws in paid components than in free ones in 2025. Attackers move fast: about half of high-impact flaws are exploited within twenty-four hours. Scores vary depending on who calculates them. And CISA’s official catalog sees almost nothing of what happens in WordPress plugins.

Time to fix, time to exploit

No fix on disclosure day

According to Patchstack, 46% of 2025 flaws had not received a fix from their developer when they were published, against 33% in 2024. Read it carefully: this does not mean these flaws will never be fixed, but that they went public before a fix existed. An update notification does not protect you against those flaws, since there is nothing to update.

Attacks within hours

Patchstack estimates that about half of the high-impact flaws of 2025 were exploited within twenty-four hours, with a weighted median of five hours before the first attack. A weekly update round is too slow for these flaws. They call for automatic updates, a web application firewall, or removing the plugin.

Old flaws remain the favorite targets

The number one target of the second quarter of 2026, according to Wordfence, is a LiteSpeed Cache flaw fixed in August 2024, with nearly 50 million blocked requests. Fixed within twelve days at the time, it is still targeted two years later, because unpatched copies are still running. Patchstack makes the same observation: of the ten most attacked flaws of 2025, only four had been published in 2025.

Forgotten sites, old staging copies or campaign sites, are the most exposed. Our WordPress maintenance checklist organizes how to keep track of them.

Abandoned and closed plugins

In 2024, according to Patchstack, 1,614 plugins and themes were removed from the official directory for unpatched flaws. The problem is that WordPress shows nothing: a closed plugin appears in the admin as an up-to-date plugin. Wordfence said so in its 2024 report: removing unused and abandoned plugins could be critically important.

The command line, however, can tell. The wporg_status field shows closed for a plugin removed from the directory, as our selection of essential WP-CLI commands shows.

wp plugin list --fields=name,status,version,update_version,auto_update,wporg_status

CVE, authorities and scores: reading a vulnerability record

Who assigns identifiers

Wordfence, Patchstack and WPScan are all three CVE Numbering Authorities, under MITRE’s supervision. According to the US NVD database, together they published more than 11,000 identifiers in 2025, nearly a quarter of all CVE identifiers published worldwide that year, by our calculation. WordPress therefore weighs heavily in the global vulnerability tracking system.

Why scores differ

The CVSS score, from 0 to 10, measures a flaw’s theoretical severity, not its risk to your site. Two authorities can score the same flaw differently, as with Elementor Pro. A core flaw scored 5.9 was nonetheless exploited in 2026.

Both vendors acknowledge it themselves: Patchstack created its own priority score because CVSS rarely rates a WordPress flaw as low severity, and Wordfence considers CVSS poorly suited to measuring real risk.

Since April 2026, the US institute NIST no longer routinely adds its own score to NVD records when the assigning authority has already provided one. The score you read is therefore, most of the time, that of the security vendor that published the flaw.

The catalog that sees almost nothing

CISA’s catalog of exploited vulnerabilities is the reference for US agencies. In early October 2026, it listed only three WordPress plugin flaws, all added in 2021, and three core flaws added in 2026. The “exploited” labels of Patchstack or Wordfence are based on their own observations. Do not confuse the two.

The day the CVE system wobbled

On April 15, 2025, MITRE warned the CVE program’s board that the US government did not intend to renew its management contract. The next day, CISA exercised an eleven-month extension option, and the service was not interrupted. The program kept running under its stewardship. For WordPress, whose vendors publish a considerable share of identifiers, an interruption would have directly disrupted vulnerability tracking.

What these numbers mean for your site

The reports paint a consistent picture. Almost all flaws are in plugins and themes, not in core. Most do not threaten an ordinary site, but the dangerous slice is growing, it is often published without a fix, and it is exploited within hours. Paid plugins, abandoned plugins and old forgotten sites concentrate the risk.

Also keep in mind that each vendor sells protection: Patchstack virtual patching, Wordfence a firewall, WPScan and Jetpack Automattic’s tools. Their figures are serious, but their conclusions often point toward their product. Our comparison of WordPress security plugins helps you choose without being driven by fear.

A prioritized action list

  1. Know exactly what is running, paid plugins included. List every plugin and theme, active or not, with its version and its status in the directory.
  2. Delete what you do not use, replace what is abandoned. A deactivated plugin keeps its files on the server.
  3. Get alerts that cover flaws without a fix. Nearly half of 2025 flaws had none at disclosure: the free feeds from Wordfence, Patchstack or WPScan flag them.
  4. Fix the dangerous slice within hours. Turn on automatic updates for plugins you trust, keep core’s on, and keep your paid licenses active so you receive fixes.
  5. When no fix exists, remove or shield. Deactivate the plugin or use a virtual patch; the free version of Wordfence gets its new rules thirty days later.
  6. Reduce what anonymous visitors and low-level accounts can reach. Close registration if it is not used, watch forms with file upload, block PHP execution in the media folder.
  7. Triage by exploitability, not by score. Ask three questions: do you need to be logged in, with which role, is the flaw exploited?
  8. Assume old flaws are still hunted. Check old sites and forgotten staging copies first.
  9. Watch for signs of intrusion and keep a way out. Unknown administrators, PHP files in the media folder, unexpected must-use plugins; and off-server backups, chosen among the WordPress backup plugins.

Summary table

Report Data What it shows Takeaway
Patchstack 2026 2025 11,334 flaws, 91% in plugins, 46% with no fix at disclosure About half of high-impact flaws exploited within 24 hours
Patchstack 2025 2024 7,966 flaws, 1,614 plugins and themes removed Closed plugins look up to date
Wordfence 2024 2024 8,223 flaws, XSS first, more than 68% low risk Access level matters more than score
Wordfence Q2 2026 April to June 2026 A 2024 flaw is still the number one target Old flaws never die
CISA catalog September 2026 Three WordPress plugin flaws, three core flaws Absent does not mean unexploited
WordPress announcements March to September 2026 37 core security fixes, by our count Keep core automatic updates on

Frequently asked questions

Is WordPress core safe?

Yes, and it is well maintained, but 2026 showed it is not immune: three of its flaws were exploited. Fixes arrive quickly and often automatically. Keep minor updates automatic.

Should I worry about every vulnerability alert?

No. First check whether the flaw requires an account, with which role, and whether it is exploited. A flaw requiring an administrator account changes almost nothing; an anonymous flaw in a plugin you use calls for action the same day.

Are paid plugins safer than free ones?

Not necessarily. According to Patchstack, they are less audited and showed three times more exploited flaws than free ones in 2025. An active license remains essential to receive fixes.

Why do Patchstack and Wordfence give different totals?

Because they do not count the same way, nor from the same reports. Compare trends within a single source, never totals from one source to another.

Does a firewall replace updates?

No. It protects while you wait for a fix, or against generic attacks. But the only lasting protection remains the update, or removing the vulnerable plugin.

What does “closed” mean in the WordPress directory?

That the plugin was removed from the official directory, often for an unpatched flaw. It no longer receives updates through that channel, and WordPress does not warn you: only a command-line check, a security tool or the plugin’s page on WordPress.org flags it.

Conclusion

WordPress vulnerability figures are frightening because people read them in bulk. Read with method, they say something precise: risk is concentrated in a small slice of serious flaws, mostly in plugins, often published without a fix and exploited within hours, and in old flaws never fixed on forgotten sites.

The Elementor Pro story demonstrates it: a paid plugin installed on millions of sites, attacked the same day, scored differently by two vendors, ignored by the official catalog. Know what is running, delete what you do not use, fix quickly and triage by exploitability: that is what these numbers ask of you.

Sources


LaFactory designs, builds and maintains WordPress and WooCommerce sites, and develops its own plugins. Talk to us about your WordPress project.

Francis Rozange

Former section editor at Libération, he runs LaFactory, an international web agency since 1996.

Cart