3Zero WordPress Security Research
Plugin vs Theme vs WordPress Core Vulnerabilities
A comparison of unique records, software associations, severity profiles, patch status and weakness patterns across WordPress software types.
How do the recorded vulnerability populations for plugins, themes and WordPress Core differ?
The comparison publishes both unique vulnerability records and vulnerability-to-software associations. Type totals can overlap when one record affects more than one software entry.
| Type | Unique records | Software associations | Distinct slugs | Critical/high records | Unpatched associations |
|---|---|---|---|---|---|
| Plugin | 35,442 | 38,151 | 15,903 | 8,698 | 10,282 |
| Theme | 2,512 | 3,110 | 2,139 | 1,398 | 1,415 |
| Core | 372 | 380 | 2 | 110 | 2 |
Why raw totals are not a quality ranking
Plugins, themes and Core are not equally sized populations. The feed also does not provide installation denominators for every software slug. These figures describe the composition of synchronized records; they do not demonstrate that an individual plugin, theme or Core release is safer solely because its category has fewer records.
Download this report’s primary data (CSV)
Data Source, Attribution and Methodology
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
Calculations use active Production Feed records in an approved, immutable snapshot. Scanner-only and source-removed records are excluded. A record count is not a direct measurement of software quality, exploitation, infection, installed-base risk or researcher productivity.
Snapshot #1 · dataset cutoff 2026-08-01 11:09:08 UTC · calculation version 1.0.0 · methodology version 1.0.0. Read the full methodology.