Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

3Zero WordPress Security Research

Patched vs Unpatched WordPress Vulnerabilities

Current synchronized patch status by software association, severity, software type and age of disclosure.

Approved snapshot #1Data through August 1, 2026 UTC38,293 active records
Research question

What proportion of synchronized software associations is currently marked patched or unpatched?

Patch status is association-level: one vulnerability may have separate software entries with their own remediation state. Status reflects the approved source snapshot, not the historical status on the original disclosure date.

Current patch-status associations
Patched29,942
Unpatched11,699
Patch status by severity
SeverityPatchedUnpatched
Critical2,020748
High6,0092,196
Medium21,7638,738
Low15017
Current age of unpatched associations
0–30 days173
31–90 days388
91–365 days2,673
More than 365 days8,465

Patch status is not compromise status

An unpatched source record does not prove that every installation is exposed, and an affected version does not prove exploitation or infection. Installed version, configuration, attack prerequisites and compensating controls still matter.

Download this report’s primary data (CSV)

Data Source, Attribution and Methodology

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Calculations use active Production Feed records in an approved, immutable snapshot. Scanner-only and source-removed records are excluded. A record count is not a direct measurement of software quality, exploitation, infection, installed-base risk or researcher productivity.

Snapshot #1 · dataset cutoff 2026-08-01 11:09:08 UTC · calculation version 1.0.0 · methodology version 1.0.0. Read the full methodology.