Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

3Zero WordPress Security Research

Five Years of WordPress Vulnerability Trends

A complete-year analysis of recorded WordPress vulnerabilities, software types, severity, weakness categories and current patch status.

Approved snapshot #1Data through August 1, 2026 UTC38,293 active records
Research question

How did recorded WordPress vulnerability disclosure volume and composition change from 2021 through 2025?

The comparison uses five complete calendar years. The current partial year is deliberately excluded from growth calculations.

Executive summary

This study examines 27,950 active WordPress vulnerability records published across five complete calendar years. It separates overall disclosure volume from affected software type, severity and normalized weakness category so that a rising count is not mistaken for proof that WordPress itself became less secure. The results describe what appears in the synchronized source dataset; they do not estimate undiscovered vulnerabilities or confirm exploitation on any website.

27,950Records published, 2021–2025
1,5142021 records
10,8312025 records
615.4%Change across the period

Five-year findings at a glance

  • Annual recorded disclosures rose from 1,514 in 2021 to 10,831 in 2025, an increase of 615.4%.
  • Plugin-associated vulnerabilities account for 95.2% of the records in the five-year series (26,604 plugin-associated records). A single vulnerability can affect more than one software entry, so software-type figures should not be added together as mutually exclusive populations.
  • 6,055 records are rated High or Critical, representing 21.7% of the five-year total. CVSS describes technical severity under stated conditions; it does not show whether exploitation occurred.
  • Cross-Site Scripting is the most frequent normalized weakness category in this period, with 12,285 records (44.0% of categorized records). Frequency is not the same as impact, but it identifies a recurring class of failure worth prioritizing in development and review.
Annual recorded vulnerabilitiesUnique active Production Feed records published in each complete year from 2021 through 2025. 10,8318,1235,4162,7080 20212022202320242025 All records: 1,514 in 2021All records: 2,396 in 2022All records: 4,892 in 2023All records: 8,317 in 2024All records: 10,831 in 2025Plugin records: 1,473 in 2021Plugin records: 2,341 in 2022Plugin records: 4,777 in 2023Plugin records: 8,006 in 2024Plugin records: 10,007 in 2025
Annual recorded vulnerabilitiesUnique active Production Feed records published in each complete year from 2021 through 2025.All recordsPlugin records
Complete-year vulnerability records by affected software type
YearAll recordsPluginThemeCoreCritical/high
20211,5141,4733410522
20222,3962,3414422848
20234,8924,77710414836
20248,3178,00630851,548
202510,83110,00782622,301

What the trend does—and does not—show

The dataset contains 1,514 records published in 2021 and 10,831 in 2025, a 615.4% change across the selected complete-year window. That is a change in recorded disclosures within this source dataset. It is not proof that the same percentage change occurred in the undiscovered vulnerability population. Research coverage, submission volume and disclosure practices also influence the series.

Most frequent normalized weakness categories, 2021–2025
Cross-Site Scripting12,285
Missing Authorization4,663
CSRF4,108
Other2,640
SQL Injection1,705
Information Disclosure814
Arbitrary File Upload643
Path Traversal509
Privilege Escalation373
Authentication Bypass210

What security teams should do with this evidence

  • Maintain a current inventory of WordPress Core, plugins and themes, including installed versions and whether each component is still supported.
  • Prioritize remediation using the affected version range, attack prerequisites, patch availability and the site’s exposure—not the CVSS number alone.
  • Remove abandoned or unnecessary extensions instead of leaving disabled code on the server indefinitely.
  • Treat an affected version as a reason to investigate and remediate, not as proof that compromise has occurred. Confirm suspicious behavior through logs, file changes, users, scheduled tasks and database review.
  • Repeat the analysis when a new approved snapshot is published. The direction of the series matters more than any isolated annual count.

Download this report’s primary data (CSV)

Data Source, Attribution and Methodology

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Calculations use active Production Feed records in an approved, immutable snapshot. Scanner-only and source-removed records are excluded. A record count is not a direct measurement of software quality, exploitation, infection, installed-base risk or researcher productivity.

Snapshot #1 · dataset cutoff 2026-08-01 11:09:08 UTC · calculation version 1.0.0 · methodology version 1.0.0. Read the full methodology.