3Zero WordPress Security Research
The Most Common WordPress Vulnerability Types
CWE-based weakness categories, their share of the dataset, severity distribution and five-year movement.
Which normalized weakness categories appear most often in records published from 2021 through 2025?
3Zero groups source CWE identifiers into intentionally broad, documented categories. Original CWE values remain available in the Vulnerability Listing.
| Category | Records | Share | Critical | High | Medium | Low |
|---|---|---|---|---|---|---|
| Cross-Site Scripting | 12,285 | 44% | 8 | 438 | 11,822 | 17 |
| Missing Authorization | 4,663 | 16.7% | 151 | 496 | 3,985 | 31 |
| CSRF | 4,108 | 14.7% | 20 | 586 | 3,497 | 5 |
| Other | 2,640 | 9.4% | 515 | 1,309 | 788 | 28 |
| SQL Injection | 1,705 | 6.1% | 310 | 820 | 575 | 0 |
| Information Disclosure | 814 | 2.9% | 12 | 82 | 710 | 10 |
| Arbitrary File Upload | 643 | 2.3% | 263 | 349 | 30 | 1 |
| Path Traversal | 509 | 1.8% | 88 | 181 | 213 | 27 |
| Privilege Escalation | 373 | 1.3% | 108 | 136 | 129 | 0 |
| Authentication Bypass | 210 | 0.8% | 132 | 51 | 24 | 3 |
Category frequency is not impact
A frequent weakness can include records with very different prerequisites and consequences. Frequency should be read beside severity and CVSS conditions, not as a substitute for them.
Download this report’s primary data (CSV)
Data Source, Attribution and Methodology
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
Calculations use active Production Feed records in an approved, immutable snapshot. Scanner-only and source-removed records are excluded. A record count is not a direct measurement of software quality, exploitation, infection, installed-base risk or researcher productivity.
Snapshot #1 · dataset cutoff 2026-08-01 11:09:08 UTC · calculation version 1.0.0 · methodology version 1.0.0. Read the full methodology.